Tag

Phishing As A Service

All articles tagged with #phishing as a service

BigBear 2.0 Phishing Service Skips MFA Across 258 Microsoft 365 Organizations
cybersecurity26 days ago

BigBear 2.0 Phishing Service Skips MFA Across 258 Microsoft 365 Organizations

A CloudSEK report details BigBear 2.0, a phishing-as-a-service framework, bypassing MFA for 258 Microsoft 365 organizations and stealing 5,137 credentials (including 474 MFA-bypassed authentications) plus 4,148 session cookies across 3,331 victims in 40+ countries. The operation used a Evilginx2-based MITM setup with an 'offy' proxy, geo-matched residential proxies, and custom JavaScript to weaken FIDO2/WebAuthn, enabling attackers to hijack sessions after victims authenticated. The admin panel remained online while the phishing infrastructure was offline for ~three weeks. Recommendations include resetting exposed passwords, revoking active sessions, refreshing tokens, enforcing phishing-resistant FIDO2/WebAuthn, and applying Conditional Access with managed devices.

Device Code Phishing Surges in 2026, Defeating MFA Across Platforms
security2 months ago

Device Code Phishing Surges in 2026, Defeating MFA Across Platforms

Device code phishing, using OAuth 2.0 device flows, has become an industrial-scale threat in 2026, enabling token theft that defeats MFA across providers via a thriving phishing-as-a-service ecosystem with 25+ kits. Attackers shift from authentication to authorization abuse, driven by AI-assisted kit development, and detection must occur at the browser during the device-code approval, since network defenses can’t block these attacks.

Global crackdown shuts down Kratos phishing kit that hijacked Microsoft 365 sessions
technology2 months ago

Global crackdown shuts down Kratos phishing kit that hijacked Microsoft 365 sessions

German and U.S. authorities dismantled Kratos, a widely used phishing kit that stole Microsoft 365 session cookies to bypass MFA, shutting down 200+ servers and affecting about 1,800 paying customers who ran some 15,000 campaigns a month. Victims number in the hundreds of thousands across 30+ countries; operators earned over €300,000 since 2024. The kit offered credential-only mode or a real-time adversary-in-the-middle reverse-proxy mode. Microsoft Threat Intelligence links it to SneakyLog; campaigns have used tax-themed W-2 emails with QR codes to lure targets. Stolen credentials can be sold or used to move laterally in Microsoft 365. Mitigations include password resets with MFA checks for credential-only hits, revoking sessions for session-stealing hits, and adopting phishing-resistant sign-ins for high-value accounts. Indicators include login-page assets barr.svg and lg.svg and endpoints like next.php or save.php. The takedown halts Kratos campaigns for now, but the kit and its customers persist elsewhere.

ARToken: A New PhaaS Armoring EvilTokens’ Microsoft 365 Toolkit
security3 months ago

ARToken: A New PhaaS Armoring EvilTokens’ Microsoft 365 Toolkit

Cisco Talos flags ARToken as a new phishing-as-a-service platform allied with EvilTokens, offering a wide toolkit to steal Microsoft 365 tokens, maintain persistence with Primary Refresh Tokens, and access Outlook, SharePoint, and OneDrive. It uses Cloudflare Workers for deployment, supports multi-tenant campaigns, and includes inbox rules, keyword monitoring, and data exfiltration tools. The kit mirrors EvilTokens’ device-code phishing flow to bypass MFA, with research suggesting a shared ecosystem and AI-enabled workflows that automate BEC-style fraud. Security teams should prioritize behavioral AI defenses and robust email security controls.

Google Sues Gemini-Powered Scam Network Tied to Outsider Enterprise
technology3 months ago

Google Sues Gemini-Powered Scam Network Tied to Outsider Enterprise

Google has filed a civil lawsuit against Outsider Enterprise, a Chinese-linked cybercrime group that used Gemini-powered scam sites and phishing templates to imitate Google, YouTube, and government sites. The operation allegedly sent millions of scam texts, created about 9,000 fake websites and 1 million URLs, and targeted hundreds of thousands of users. Google is working with law enforcement and mobile carriers to disrupt the network, aided by on-device scam detection in Google Messages, and is pushing for new AI-scam legislation.