KitWatch — Karen IT

The Repository
of Real Phishing Kits.

KitWatch is Karen IT's curated repository of phishing kits collected in the wild — real attack infrastructure, preserved and made accessible to security researchers, CERTs, and anti-phishing teams for defensive research and threat intelligence.

⚠️   Access is restricted — vetted organizations only
Recently Added Kits
Real Wild-caught samples
Vetted Access only
Active Continuously updated
KSRC Managed by
The Fundamentals

What Is a
Phishing Kit?

A phishing kit is a ready-to-deploy package that lets cybercriminals stand up a convincing fake website in minutes. Understanding them is the first step to detecting and disrupting the campaigns built on them.

📦

What It Contains

HTML pages that mimic legitimate sites, PHP scripts that capture and exfiltrate stolen credentials, images and assets copied from real brands, and configuration files specifying where to send harvested data.

Why It's Dangerous

A kit requires no technical skill to deploy. Anyone can upload it to a compromised server and begin harvesting credentials within minutes. This is why phishing scales — the barrier to entry is almost zero.

🔄

How They Spread

Kits are sold on criminal forums, shared freely in Telegram channels, and reused across hundreds of campaigns. The same kit may be deployed by dozens of different actors simultaneously across unrelated infrastructure.

🔍

What They Reveal

Analyzing a phishing kit exposes the attacker's exfiltration infrastructure, the brands they're targeting, evasion techniques they use to avoid detection, and code patterns that link multiple campaigns to the same actor.

paypal-kit-v3.zip — extracted
📁 paypal-kit-v3/
  ├── index.php ← landing page, geo-check
  ├── login.php ← credential harvester
  ├── send.php ← exfil to attacker email
  ├── .htaccess ← blocks security scanners
  ├── 📁 assets/ ← copied PayPal CSS/JS
  └── 📁 img/ ← cloned brand images
Why KitWatch Exists

You Cannot Defend Against
What You Haven't Analyzed.

Phishing kits are the infrastructure behind the majority of credential-stealing attacks. A repository of real, wild-caught kits gives the security community something they rarely have — the attacker's actual tools.

🧬

YARA Rule Development

Real kit samples enable researchers to develop YARA rules and detection signatures based on actual code patterns, rather than hypothetical scenarios. Rules constructed from real kits are effective in detecting real deployments.

🔗

Campaign Attribution

Phishing kits contain unique code signatures, commenting styles, and infrastructure references that link seemingly unrelated campaigns to the same actor. Kit analysis is one of the most effective attribution methods available.

🎯

Target Intelligence

Every kit is built to impersonate a specific target. Analyzing the repository reveals which brands and sectors are being targeted most heavily — and which attack techniques are currently being used against them.

⚙️

Evasion Technique Research

Modern phishing kits contain sophisticated evasion techniques — Cloudflare bypass, bot detection, IP geofencing, and security scanner blocking. Understanding these techniques is essential to improving detection tools.

🌐

Infrastructure Mapping

Kit configuration files reveal exfiltration endpoints — email addresses, Telegram bots, and backend servers. These indicators can be used to map and disrupt the attacker's full operational infrastructure.

📚

Training & Education

Real phishing kits are the most effective training material for security analysts learning to recognize, investigate, and respond to phishing campaigns. No simulation comes close to the real thing.

What's in the Repository

Not Just Files.
Structured Intelligence.

Every kit in KitWatch is documented, classified, and contextualized — not simply archived. Members receive structured intelligence, not raw zip files.

01

Authentic Wild-Caught Samples

Every kit in the repository was collected from active phishing infrastructure — not constructed or modified. What you analyze is what the attacker actually deployed.

02

Classification & Metadata

Each kit is classified by targeted brand, attack type, evasion techniques present, exfiltration method, and observed deployment date — enabling rapid filtering and analysis.

03

Screenshot Evidence

Screenshots of the kit as deployed — showing the fake login page, any multi-step flows, and the visual impersonation technique used — captured at the time of collection.

04

Infrastructure Context

The hosting infrastructure, domain, registrar, and IP data associated with the kit at the time of collection — enabling correlation with other incidents and campaigns.

05

Kit Fingerprints & Hashes

File hashes and structural fingerprints for every kit — enabling rapid identification of the same kit deployed on new infrastructure, even when the domain and hosting change.

06

Continuous Updates

KitWatch is not a static archive. New kits are added as they are identified through Karen IT's CTI platform, URLAbuse detection systems, and KSRC case intake.

Access & Eligibility

Access Is Restricted.
For Good Reason.

Phishing kits are live attack tools. KitWatch exists to advance defensive research — not to lower the barrier to launching attacks. Every access request is reviewed individually.

🔬

Security Researchers

Researchers studying phishing techniques, attacker infrastructure, and campaign attribution — at academic institutions, security companies, or independently with a demonstrated track record.

🌐

CERTs & CSIRTs

National and sectoral computer emergency response teams that handle phishing incidents and need access to kit samples to support investigations and improve detection capabilities.

🏢

Anti-Phishing Teams

Security teams at organizations that are frequent phishing targets — financial institutions, payment providers, technology companies — and need kit samples to develop and test detection.

🛡️

Security Vendors

Security product companies developing anti-phishing detection, email security, or web filtering products that need real kit samples to test and improve their detection engines.

📋

Registrars & Registries

Domain registrars and registries that receive phishing abuse reports and need kit analysis to support suspension decisions and identify patterns of infrastructure abuse.

🎓

Academic Institutions

Universities and research institutions conducting peer-reviewed cybersecurity research on phishing, social engineering, or attacker infrastructure — with appropriate ethical oversight.

⚠️
KitWatch is not for penetration testers or red teams. The repository contains real attack tools that were used against real victims. Access is granted exclusively for defensive research and intelligence purposes. Requests from penetration testing firms, red teams, or individuals without a clear defensive research purpose will not be approved.
How to Request Access

Four Steps.
Straightforward Process.

We review every request. The process is thorough but not complicated.

01

Submit Request

Complete the access request form on ksrc.karenit.net/kitwatch. Describe your organization, role, and intended use of the repository.

02

Review

The KSRC team reviews your request against our eligibility criteria. We may follow up with questions about your intended research use.

03

Agreement

Approved requestors sign a usage agreement confirming that access is for defensive research only and that kits will not be deployed or redistributed.

04

Access Granted

You receive access credentials and onboarding information. New kits are added regularly — you'll have access to the full repository and all future additions.

The Kits Are Real.
The Research Should Be Too.

KitWatch gives defenders access to the actual tools attackers are using. If your work involves detecting, disrupting, or researching phishing campaigns — this repository was built for you.