Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungI audited my own ML linter and had to withdraw its best evidence(21.09.2026 um 22:54 Uhr)
Sichere ProgrammierungQuantum Result Validation for Distributed Computing Systems(21.09.2026 um 22:54 Uhr)
Sichere ProgrammierungJWT Authentication and Role-Based Access Control in LocalHands(21.09.2026 um 22:56 Uhr)
Sichere ProgrammierungStochastic Parrot or Alien Mind?(21.09.2026 um 22:56 Uhr)
Sichere ProgrammierungBuilding AI for the Physical World Is a Different Engineering Problem(21.09.2026 um 22:58 Uhr)
Sichere ProgrammierungI audited my own ML linter and had to withdraw its best evidence(21.09.2026 um 22:54 Uhr)
Sichere ProgrammierungQuantum Result Validation for Distributed Computing Systems(21.09.2026 um 22:54 Uhr)
Sichere ProgrammierungJWT Authentication and Role-Based Access Control in LocalHands(21.09.2026 um 22:56 Uhr)
Sichere ProgrammierungStochastic Parrot or Alien Mind?(21.09.2026 um 22:56 Uhr)
Sichere ProgrammierungBuilding AI for the Physical World Is a Different Engineering Problem(21.09.2026 um 22:58 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Anglerphish — A Feature-Rich Gophish Fork

Anglerphish — A Feature-Rich Gophish ForkFrom Side Project to an Upgraded Gophish PlatformIf you work in cyber security, chances are you’ve come across Gophish at some point — whether in testing, labs, or real engagements.But once you move …

0
↗ Quelle (infosecwriteups.com)
Reagiere als Erste:r — dein Feedback zählt!

Anglerphish — A Feature-Rich Gophish Fork

From Side Project to an Upgraded Gophish Platform

If you work in cyber security, chances are you’ve come across Gophish at some point — whether in testing, labs, or real engagements.

But once you move beyond basic setups, its limitations become clear: single-vector campaigns, lack of orchestration, and a lot of repetitive manual work.

Like many others, I started with basic local campaigns before gradually moving into production deployments. As I began using it in real client engagements.

The deeper I worked with the platform, the more I explored its internals and community-driven modifications. Eventually, one question came up:

Why not extend it myself?

Inspired by community-driven modifications and tools like Evilgophish, I began building extensions on top of Gophish while keeping its familiar workflows intact.

What began as a small, fun, side project, gradually evolved into the fork I now call Anglerphish.

Notable Enhancements

Over time, this fork grew beyond what I initially set out to build and now includes more changes than would fit in a single article. Below are a few highlights that had the most practical impact.

Multi-Vector Campaign Support

Traditional phishing simulations tend to revolve around email. And while that still works, real-world attacks have clearly moved beyond a single vector.

Anglerphish expands the campaign engine to support:

  • Native SMS campaigns (Twilio & Vonage support) — following the same familiar workflow as email campaigns, but adapted for SMS delivery.
  • QR code campaigns — generated dynamically through a simple placeholder parameter, enabling seamless embedding into emails, landing pages, or documents.
  • HTTP Basic Authentication landing flows — replacing traditional HTML landing pages with a browser-native authentication prompt for infrastructure-style scenarios.
  • Generic campaigns for off-channel distribution (QR posters, offline delivery, internal messaging, etc.) — allowing fully hostable, trackable landing pages to be generated and shared through virtually any medium.
  • MFA simulation with OTP tracking (Sent / Verified / Failed) — integrated directly into the existing campaign flow and enabled through landing page configuration, without requiring a separate campaign type.

The MFA functionality is not designed to replicate full real-time interception frameworks such as Evilginx. Instead, it leverages integrated email and SMS flows to simulate realistic multi-step authentication scenarios within the same platform.

Of course the possibilities of integrations are endless and there’s still room to expand!

Generic Campaign creation preview.
Campaign Creation Preview
HTTP Basic Auth Landing Page

Campaign Orchestration at Scale

One of the most frustrating parts of working with Gophish during larger engagements was orchestration.

There’s no “save as draft” workflow. Each campaign must be launched or scheduled before you can move on. And if you realize something needs adjusting after launch, the only option is to delete and recreate it from scratch.

That friction led to the idea of Campaign Sets — a way to prepare and manage multiple campaigns before launching anything.

Campaign Sets allow multiple campaigns (Email and SMS) to be grouped and configured together. Each campaign can maintain its own settings, while shared parameters — such as landing pages, URLs, or launch schedules — can be defined across the entire set.

Most importantly, sets can be saved as drafts. You can iterate, review, and refine before executing — making multi-scenario assessments significantly easier to plan and manage.

Preview of the creation of a draft campaign set
Draft Campaign Set Creation Preview

Once launched, campaigns behave exactly as they normally would and remain individually accessible for monitoring and reporting.

Reporting Support

Reporting is often one of the most time-consuming parts of phishing engagements — not because it’s complex, but because it’s repetitive.

Exporting CSVs, building charts, and formatting results into client-ready reports quickly becomes a manual and time-consuming process.

To address this, I added a dedicated Reports to Anglerphish. Campaign results can now be exported directly as structured Word or Excel reports.

These reports may not replace fully customized deliverables, but they provide clean, presentation-ready content that significantly reduces manual post-processing time.

Reports can be generated for individual campaigns or entire campaign sets. Privacy options allow partial anonymization of sensitive data — such as email addresses, phones or IPs — making it easier to share results with clients or external stakeholders.

The reporting engine is powered by Python and includes built-in environment checks to ensure required dependencies are available, streamlining setup.

Reports Section Preview

Security Improvements Within the Platform

Gophish so far had no database encryption, leaving exposed SMTP or IMAP configuration passwords, and of course target passwords when collected.

Anglerphish introduces optional, application-level AES-256-GCM encryption for sensitive database fields, including SMTP credentials, SMS provider keys, IMAP passwords, and captured data.

Encryption is controlled via environment configuration, remains fully backward compatible, and includes migration support — allowing existing deployments to transition to an encrypted state without breaking functionality.

Migrating Sensitive Fields to Encrypted State
“Skipped” includes rows where there are no event details (i.e., Email Sent, Campaign Created)

Additional Improvements

Beyond the features highlighted above, Anglerphish includes several refinements, additions, and quality-of-life improvements such as:

  • URL templates for reusable complex structures
  • Email, SMS, and Landing Page template previews for quick content review
  • Enhanced IMAP monitoring, supporting multiple configurations and tracking both email Replies and Reported messages
  • Expanded template variables for dynamic personalization
  • In-app documentation for newly introduced features

All being well, I may share more detailed breakdowns of specific features in the future and continue expanding the platform.

The complete feature set is documented in the GitHub repository. If this sounds interesting, I encourage you to explore it and experiment with the fork yourself. If you find it useful, a star on GitHub is always appreciated.

Anglerphish is not intended to replace Gophish, but to extend it in ways shaped by real-world operational needs.

As real-world engagements grow in complexity, tooling needs to evolve to remain practical and efficient. This project is a step in that direction.

What began as incremental improvements evolved into a more flexible platform for phishing simulations — built with compatibility, practicality, and security in mind.

Project Repository


Anglerphish — A Feature-Rich Gophish Fork was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Anglerphish — A Feature-Rich Gophish Fork

Thematisch verwandte Begriffe: Anglerphish  A, FeatureRich, Gophish, Fork · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-79918 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick