A New Era of Brand-Deceptive Phishing: Inside the CoGUI Framework
A newly uncovered phishing infrastructure known as CoGUI is rapidly gaining notoriety for its aggressive and large-scale campaigns, particularly against Japanese organizations. Since October 2024, it has been responsible for distributing millions of phishing emails in a coordinated, highly targeted effort.
Disguised as communications from major brands like Amazon, PayPay, and Rakuten, as well as several financial institutions, CoGUI campaigns lure victims by exploiting the visual and linguistic cues of trusted platforms. These impersonations are designed to trick users into surrendering personal credentials and financial details.
The campaign scale is staggering—ranging from several hundred thousand to over ten million messages per operation—placing Japan among the top global hotspots for phishing attacks by volume.
Attackers leverage polished, urgency-laden messages that prompt recipients to follow embedded links. These URLs direct victims to convincingly forged login portals, where sensitive data is silently captured.
Recent waves of attacks have also capitalized on topical geopolitical developments, including fake tariff notifications following U.S. trade policy updates—a tactic that adds realism and increases click-through likelihood.
Cybersecurity analysts at Proofpoint first flagged the CoGUI phishing kit in December 2024 and have monitored its rapid evolution since. Notably, January 2025 marked the campaign’s most active period, with more than 172 million malicious messages detected in a single month.
Although Japan remains the central focus, CoGUI’s footprint has expanded. Evidence now shows spillover activity targeting individuals in Australia, New Zealand, Canada, and the United States.
What elevates CoGUI above conventional phishing kits is its blend of adaptive evasion strategies and its ability to capture an extensive range of personal and financial data with alarming precision.

Payment Data Theft at the Core of CoGUI’s Strategy
(Source: Proofpoint)
CoGUI’s phishing infrastructure goes far beyond harvesting login credentials—it’s engineered to siphon payment card data as well, dramatically raising the stakes for unsuspecting users. Victims face not just compromised accounts, but direct financial exposure.
These operations mirror warnings recently issued by Japan’s Financial Services Agency, which highlighted a surge in phishing schemes linked to monetary fraud.
Stealth by Design: CoGUI’s Anti-Detection Arsenal
What sets CoGUI apart from less sophisticated phishing tools is its intricate evasion architecture. At the heart of this system is a refined browser fingerprinting mechanism designed to sidestep detection and ensure only human targets are engaged.
The kit stealthily collects a wide array of environmental data, including:
- IP-based geolocation
- Browser language and version
- Operating system and screen resolution
- Device classification (desktop, mobile, tablet, etc.)
This information enables CoGUI to carry out two critical tasks:
- Selectively filter targets based on geography or device context
- Bypass automated scanning tools, which often fail the kit’s validation checks
Before serving a phishing payload, CoGUI evaluates the visitor’s browser profile to determine whether the session appears genuine. Only then does it deliver the malicious content, avoiding wasted effort on bots or sandboxed environments.

Fake PayPay Login Pages Tailored by CoGUI
(Source: Proofpoint)
Once a visitor’s browser passes CoGUI’s fingerprinting checks, the phishing framework deploys a counterfeit login page aimed at harvesting user credentials. But if the environment doesn’t meet specific criteria—such as geographic location or browser setup—the framework initiates a clean redirect to the legitimate site it’s impersonating.
For example, someone accessing a spoofed “Amazon.co.jp” link from an unqualified profile would be forwarded directly to the real Amazon Japan homepage, leaving no sign of the deception attempt.
This intelligent fallback mechanism not only helps CoGUI evade detection by security crawlers and researchers but also reinforces the illusion of legitimacy for the user. It’s a surgical approach to targeting that minimizes noise and maximizes success.
By combining geolocation filters, HTTP header inspection, and environment validation, CoGUI ensures its phishing assets are exposed only to users who fit a precise mold. This level of sophistication has led analysts at Proofpoint to conclude the kit is likely being weaponized by multiple China-based actors, with a sharp focus on Japanese-speaking victims.




