• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

War Room

Shells From Above

RSM logo

  • Home
  • About
  • Blog
  • Talks/Whitepapers
  • Tools
  • Recreation
Home > R&D > Development > King Phisher 0.2.1 Released

King Phisher 0.2.1 Released

July 15, 2015 By Spencer

Yesterday, RSM released the latest version of their King Phisher phishing campaign toolkit. This version adds some exciting new features with a focus on usability.

King Phisher Message Editor
The new King Phisher message editor tab.

The message editor received some nice improvements, including syntax highlighting. The editor window now uses the GtkSourceView project to provide a more user friendly environment for writing and modifying message templates. Furthermore if users choose not to use the integrated message editor and instead opt to use an external editor, changes made to the document will be reflected in the King Phisher client. This makes editing messages using the integrated editor easier. Additionally users that might not have been aware of it’s existence should checkout the right click menu in the editor for easy access to common Jinja tags without needing to remember the exact syntax.

Some additional features have also been added at the request of some users. The King Phisher server can now be configured to use an IP address provided by a cookie. This feature can be enabled from the server configuration file to allow the server to be located behind a proxy. Also it is now easier than ever to embed training videos hosted on You Tube into server pages. A single Jinja function can be used to embed a video by it’s ID. Many times though it is requested that users watch the entire video before being able to accept training. While the use of JavaScript limits what the page can “force” a user to do, King Phisher does make a best effort attempt to ensure that the training element of the HTML page is disabled until the video has finished playing.

King Phisher has also had a fantastic new Metasploit plugin submitted by community user coldfusion39. This plugin for msfconsole is available in the data/msf directory and uses the King Phisher server’s optional REST API to send SMS messages when new sessions are opened. This is a very handy feature if users are expecting sessions to be opened from the emails that they are sending.

Finally, the King Phisher client has new support for exporting geographic information regarding visits to the popular GeoJSON format. This allows the information to optionally be loaded into third party services such as geojson.io for additional analysis. The new GeoJSON format is available from the File > Export menu within the client.

As always, King Phisher is available on RSM’s GitHub page and can be downloaded here: https://github.com/securestate/king-phisher. We welcome any feedback you may have. Have a good idea for a useful feature you would like to see us add? Submit a feature request by opening a ticket on the issues page.

Happy Phishing!

Spencer

Primary Sidebar

Categories

  • Defense
  • Forensics
  • Offense
  • Physical
  • R&D

Most Viewed Posts

  • DLL Injection Part 1: SetWindowsHookEx 11.1k views
  • Sophos UTM Home Edition – 3 – The Setup 10.9k views
  • Leveraging MS16-032 with PowerShell Empire 10.1k views
  • Bypassing Gmail’s Malicious Macro Signatures 10k views
  • How to Bypass SEP with Admin Access 9.1k views

Footer

  • Facebook
  • LinkedIn
  • Twitter
  • Tools
  • About
  • RSM US LLP

(312) 634-3400

30 S. Wacker Drive Suite 3300
Chicago, IL 60606

Copyright © 2026 RSM US LLP. All rights reserved. RSM US LLP is a limited liability partnership and the U.S. member firm of RSM International, a global network of independent audit, tax and consulting firms. The member firms of RSM International collaborate to provide services to global clients, but are separate and distinct legal entities that cannot obligate each other. Each member firm is responsible only for its own acts and omissions, and not those of any other party. Visit for more information regarding RSM US LLP and RSM International.