A Party-Invite Phish, Watched Live
Ten days after the Punchbowl phish, a Partiful-themed invite arrived the same way: from a real, compromised Gmail account, blind-copied to its contacts. This one runs on a different kit, a PHP fake Google sign-in with a live operator panel, reached through a QR-code redirect the operator can repoint at will. A honeypot run watched the operator check a password in 12 seconds and take over a test account in about a minute. Here is the chain, the timing, and signatures for hunting it.