




3DBlast: New Active Multibrand And Multiflow Phishkit Detected
Observed in the US, it impersonates Microsoft 365, Office 365, and Google while rotating infrastructure and phishing flows.
We observed BitB, OAuth/Device Code phishing, AiTM, and DOM relay — techniques that let attackers mimic legitimate login experiences, abuse trusted authentication flows, intercept sessions, and relay victim interactions in real time.
See the analysis sessions and collect IOCs to speed up detection and response:
- https://app.any.run/tasks/f433e34a-985e-45db-b6d9-2d1159467ecf
- https://app.any.run/tasks/643119a6-6456-4c6b-96d8-cfaf034e419f/
Use this TI Lookup query to pivot from IOCs, review related activity, and validate your detection coverage.
IOCs:
llove-kitchens[.]com
createashape[.]com
ojpho7hhniua5lcd6jdgjpb161z[.]workers[.]dev
liguigas[.]com
ogqiatl1g63gs9oz1xyvufz5u[.]workers[.]dev
jarvissingaspore[.]com
dnavp5upvhaphzpbef8lf90p[.]workers[.]dev
visinomics[.]com
resultbusiness[.]com
w5fc40y5m7ehl190zcipbw[.]workers[.]dev
sansgiorgiosrl[.]com
2026-global-tender-collaborations[.]workers[.]dev
xxpn8dakpd8cr5pdt2ii[.]workers[.]dev