Tag

Phishing As A Service

All articles tagged with #phishing as a service

Device Code Phishing Surges in 2026, Defeating MFA Across Platforms
security2 days ago

Device Code Phishing Surges in 2026, Defeating MFA Across Platforms

Device code phishing, using OAuth 2.0 device flows, has become an industrial-scale threat in 2026, enabling token theft that defeats MFA across providers via a thriving phishing-as-a-service ecosystem with 25+ kits. Attackers shift from authentication to authorization abuse, driven by AI-assisted kit development, and detection must occur at the browser during the device-code approval, since network defenses can’t block these attacks.

Global crackdown shuts down Kratos phishing kit that hijacked Microsoft 365 sessions
technology12 days ago

Global crackdown shuts down Kratos phishing kit that hijacked Microsoft 365 sessions

German and U.S. authorities dismantled Kratos, a widely used phishing kit that stole Microsoft 365 session cookies to bypass MFA, shutting down 200+ servers and affecting about 1,800 paying customers who ran some 15,000 campaigns a month. Victims number in the hundreds of thousands across 30+ countries; operators earned over €300,000 since 2024. The kit offered credential-only mode or a real-time adversary-in-the-middle reverse-proxy mode. Microsoft Threat Intelligence links it to SneakyLog; campaigns have used tax-themed W-2 emails with QR codes to lure targets. Stolen credentials can be sold or used to move laterally in Microsoft 365. Mitigations include password resets with MFA checks for credential-only hits, revoking sessions for session-stealing hits, and adopting phishing-resistant sign-ins for high-value accounts. Indicators include login-page assets barr.svg and lg.svg and endpoints like next.php or save.php. The takedown halts Kratos campaigns for now, but the kit and its customers persist elsewhere.

ARToken: A New PhaaS Armoring EvilTokens’ Microsoft 365 Toolkit
security1 month ago

ARToken: A New PhaaS Armoring EvilTokens’ Microsoft 365 Toolkit

Cisco Talos flags ARToken as a new phishing-as-a-service platform allied with EvilTokens, offering a wide toolkit to steal Microsoft 365 tokens, maintain persistence with Primary Refresh Tokens, and access Outlook, SharePoint, and OneDrive. It uses Cloudflare Workers for deployment, supports multi-tenant campaigns, and includes inbox rules, keyword monitoring, and data exfiltration tools. The kit mirrors EvilTokens’ device-code phishing flow to bypass MFA, with research suggesting a shared ecosystem and AI-enabled workflows that automate BEC-style fraud. Security teams should prioritize behavioral AI defenses and robust email security controls.

Google Sues Gemini-Powered Scam Network Tied to Outsider Enterprise
technology1 month ago

Google Sues Gemini-Powered Scam Network Tied to Outsider Enterprise

Google has filed a civil lawsuit against Outsider Enterprise, a Chinese-linked cybercrime group that used Gemini-powered scam sites and phishing templates to imitate Google, YouTube, and government sites. The operation allegedly sent millions of scam texts, created about 9,000 fake websites and 1 million URLs, and targeted hundreds of thousands of users. Google is working with law enforcement and mobile carriers to disrupt the network, aided by on-device scam detection in Google Messages, and is pushing for new AI-scam legislation.