CoGUI Chaos: Massive Phishing Frenzy Targets Millions Worldwide!
Meet CoGUI, the phishing kit that sends more emails than your grandma trying to remind you about family reunions. With over 580 million emails sent in months, it’s the highest-volume campaign Proofpoint tracks. Mostly targeting Japan, CoGUI proves that even phishing kits can have a favorite vacation spot!

Hot Take:
Looks like the CoGUI phishing kit is the new rockstar of cyber-attacks, sending more emails than my inbox can handle and fooling half the internet with fake Amazon receipts and Apple invoices. It’s like a digital game of whack-a-mole, but instead of moles, we’ve got 580 million emails, and instead of whacking, we’re just desperately trying not to click on anything suspicious. Looks like we all need to take a crash course in ‘Not-Getting-Scammed 101’ because CoGUI is setting new records in the phishing Olympics!
Key Points:
- CoGUI phishing kit blasted 580 million emails from January to April 2025.
- Top impersonated brands include Amazon, Rakuten, PayPal, and Apple.
- January saw the zenith with 172 million phishing emails in 170 campaigns.
- While Japan is the main target, attacks also reached the US, Canada, Australia, and New Zealand.
- CoGUI is a separate entity from the Darcula phishing kit, though both are linked to Chinese operatives.