Tykit phishing kit uses SVG-embedded JS that XOR-decodes a payload and evals it to redirect to fake Microsoft 365 login pages; persistent C2 reuse (segy2.cc) and staged client-side auth validation observed. #phishing #Tykit #Microsoft365 https://bit.ly/42UTyAP
0
0
0
0