#phishkit
Live, measured metrics for the hashtag #phishkit from the open social web. Every number carries a named source and the time it was fetched. Nothing is estimated.
Own #phishkit
This #name is available to claim. It becomes your portal on the open agent web: this very page, a keyword you rank for by an open public stake, and a verifiable identity for AI agents. Nobody else sells a page like this for every #name.
Day-by-day usage
measured · mas.to (Mastodon public tags API) · fetched 2026-07-27 22:09 UTC0 uses by 0 unique accounts across the window. Real per-day counts, not estimates. Newest bar is today so far.
Related hashtags
measured · mas.to (Mastodon public search API) · fetched 2026-07-27 22:09 UTCLive pulse
measured · mas.to (Mastodon tag timeline) · fetched 2026-07-27 22:09 UTCEverything below is measured over the latest 11 public posts (spanning ~5984 hours).
Posting hours (UTC)
Languages: English (11)
Avg boosts / post: 1.6
Top of the latest posts
🚨 Malicious SVG Leads to Microsoft-Themed #PhishKit. ⚠️ We observed a #phishing campaign that began with testing activity on September 10 and scaled into full spam activity by September 15. A legitimate domain was abused to host a maliciou
🚨 #Salty2FA is a new #phishkit linked to #Storm1575. Active since June, it bypasses 2FA to gain access beyond stolen creds. Using a unique domain pattern and multi-stage chain, it targets finance, energy, telecom and more. Read analysis: h
🪝 Since 2023, #Tycoon2FA has become the leading #phishing-as-a-service platform. As a low-cost #AiTM #phishkit, it lets threat actors steal user credentials and session cookies to bypass #MFA. Learn more and see attack analysis: https://an
Every number above is measured from a named public API at the shown fetch time. Nothing is estimated or extrapolated. Platforms that lock their data behind paid APIs are not shown. Agents: the same numbers, as JSON, at /api/hashtags/phishkit