<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #AitM</title><description>Cybersecurity articles tagged #AitM on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Dismantling Kratos: Law Enforcement Disrupts Phishing-as-a-Service Hub</title><link>https://runtimerebel.com/blog/dismantling-kratos-law-enforcement-disrupts-phishing-as-a-service-hub</link><guid isPermaLink="true">https://runtimerebel.com/blog/dismantling-kratos-law-enforcement-disrupts-phishing-as-a-service-hub</guid><description>Law enforcement agencies dismantle the Kratos PhaaS platform, arresting its developer and disrupting infrastructure used for high-scale session cookie theft.</description><pubDate>Wed, 22 Jul 2026 02:46:13 GMT</pubDate><category>Kratos PhaaS</category><category>AitM</category><category>Phishing as a Service</category><category>Cybercrime Takedown</category><category>Credential Theft</category></item><item><title>Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks</title><link>https://runtimerebel.com/blog/forg365-phaas-bypassing-mfa-in-microsoft-365-via-aitm-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/forg365-phaas-bypassing-mfa-in-microsoft-365-via-aitm-attacks</guid><description>Forg365 PhaaS enables attackers to compromise Microsoft 365 accounts using AI-assisted lures and device code phishing to bypass multi-factor authentication.</description><pubDate>Mon, 13 Jul 2026 14:38:14 GMT</pubDate><category>Forg365</category><category>Microsoft 365</category><category>PhaaS</category><category>AitM</category><category>Device Code Phishing</category></item><item><title>Evilginx Operations Exposed: Misconfigured Server Leaks M365 Phishing Kits</title><link>https://runtimerebel.com/blog/evilginx-operations-exposed-misconfigured-server-leaks-m365-phishing-kits</link><guid isPermaLink="true">https://runtimerebel.com/blog/evilginx-operations-exposed-misconfigured-server-leaks-m365-phishing-kits</guid><description>A misconfigured Python server exposed three live Evilginx phishing operations targeting Microsoft 365, revealing the attacker&apos;s toolkit and session cookies.</description><pubDate>Mon, 13 Jul 2026 11:18:10 GMT</pubDate><category>Evilginx</category><category>Microsoft 365</category><category>Phishing</category><category>AitM</category><category>MFA Bypass</category></item><item><title>Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise</title><link>https://runtimerebel.com/blog/forg365-phaas-leverages-ai-aitm-for-microsoft-365-account-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/forg365-phaas-leverages-ai-aitm-for-microsoft-365-account-compromise</guid><description>Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing.</description><pubDate>Thu, 09 Jul 2026 15:14:50 GMT</pubDate><category>Forg365</category><category>Phishing as a Service</category><category>PhaaS</category><category>Microsoft 365</category><category>AitM</category><category>AI Phishing</category><category>Device Code Phishing</category></item><item><title>BlackFile: Analyzing UNC6671 Vishing &amp; Cloud Data Extortion</title><link>https://runtimerebel.com/blog/blackfile-analyzing-unc6671-vishing-cloud-data-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/blackfile-analyzing-unc6671-vishing-cloud-data-extortion</guid><description>Examines UNC6671&apos;s BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 &amp; Okta. Actionable mitigations included.</description><pubDate>Fri, 15 May 2026 20:32:33 GMT</pubDate><category>UNC6671</category><category>BlackFile</category><category>Vishing</category><category>AitM</category><category>Microsoft 365</category><category>Okta</category><category>SharePoint</category><category>OneDrive</category><category>Data Exfiltration</category><category>Extortion</category><category>Social Engineering</category></item><item><title>AitM Phishing Attacks Target US Organizations with Conduct Reports</title><link>https://runtimerebel.com/blog/aitm-phishing-attacks-target-us-organizations-with-conduct-reports</link><guid isPermaLink="true">https://runtimerebel.com/blog/aitm-phishing-attacks-target-us-organizations-with-conduct-reports</guid><description>Microsoft warns of a sophisticated AitM phishing campaign using fake conduct reports to bypass MFA and hijack Microsoft 365 user sessions.</description><pubDate>Tue, 05 May 2026 16:40:58 GMT</pubDate><category>Phishing</category><category>AitM</category><category>Microsoft 365</category><category>Session Hijacking</category><category>Credential Theft</category></item><item><title>Tycoon 2FA Market Shift: Fragmentation and the Rise of Dadsec</title><link>https://runtimerebel.com/blog/tycoon-2fa-market-shift-fragmentation-and-the-rise-of-dadsec</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-market-shift-fragmentation-and-the-rise-of-dadsec</guid><description>Analysis of Tycoon 2FA&apos;s declining market share as threat actors reuse its technical artifacts in Dadsec and other phishing-as-a-service platforms.</description><pubDate>Sat, 18 Apr 2026 12:18:24 GMT</pubDate><category>Tycoon 2FA</category><category>Dadsec</category><category>Phishing as a Service</category><category>AitM</category><category>MFA Bypass</category></item><item><title>AitM Phishing Campaign Targets TikTok Business via Turnstile Evasion</title><link>https://runtimerebel.com/blog/aitm-phishing-campaign-targets-tiktok-business-via-turnstile-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/aitm-phishing-campaign-targets-tiktok-business-via-turnstile-evasion</guid><description>Security researchers have identified a sophisticated AitM phishing campaign using Cloudflare Turnstile to hijack TikTok for Business accounts for malvertising.</description><pubDate>Fri, 27 Mar 2026 16:23:55 GMT</pubDate><category>Tiktok</category><category>AitM</category><category>Phishing</category><category>Cloudflare Turnstile</category><category>Malvertising</category><category>Credential Hijacking</category></item><item><title>Tycoon 2FA PaaS Recovery: Detecting AitM Phishing Infrastructure</title><link>https://runtimerebel.com/blog/tycoon-2fa-paas-recovery-detecting-aitm-phishing-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-paas-recovery-detecting-aitm-phishing-infrastructure</guid><description>Tycoon 2FA Phishing-as-a-Service has recovered from law enforcement disruption. Learn how this AitM platform bypasses MFA and how to protect your organization.</description><pubDate>Mon, 23 Mar 2026 12:24:24 GMT</pubDate><category>Tycoon 2FA</category><category>AitM</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>Credential Theft</category></item><item><title>Tycoon 2FA PhaaS Infrastructure Dismantled in Europol-Led Operation</title><link>https://runtimerebel.com/blog/tycoon-2fa-phaas-infrastructure-dismantled-in-europol-led-operation</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-phaas-infrastructure-dismantled-in-europol-led-operation</guid><description>Europol and global law enforcement dismantle Tycoon 2FA, a Phishing-as-a-Service kit used in 64,000 attacks to bypass MFA via AitM techniques.</description><pubDate>Thu, 05 Mar 2026 08:16:06 GMT</pubDate><category>Tycoon 2FA</category><category>Europol</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>AitM</category></item><item><title>Tycoon 2FA PhaaS Platform Dismantled in Global Law Enforcement Takedown</title><link>https://runtimerebel.com/blog/tycoon-2fa-phaas-platform-dismantled-in-global-law-enforcement-takedown</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-phaas-platform-dismantled-in-global-law-enforcement-takedown</guid><description>International law enforcement dismantled Tycoon 2FA, a Phishing-as-a-Service platform used to bypass MFA and target 500,000 organizations monthly.</description><pubDate>Wed, 04 Mar 2026 20:15:37 GMT</pubDate><category>Tycoon 2FA</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>AitM</category><category>Europol</category></item><item><title>Starkiller Phishing-as-a-Service: Technical Analysis of Adversary-in-the-Middle Frameworks</title><link>https://runtimerebel.com/blog/starkiller-phishing-as-a-service-technical-analysis-of-adversary-in-the-middle-frameworks</link><guid isPermaLink="true">https://runtimerebel.com/blog/starkiller-phishing-as-a-service-technical-analysis-of-adversary-in-the-middle-frameworks</guid><description>An examination of the Starkiller phishing platform, which employs transparent reverse proxy techniques to relay authentication traffic and capture multi-factor…</description><pubDate>Mon, 23 Feb 2026 08:20:40 GMT</pubDate><category>Phishing</category><category>MFA Bypass</category><category>AitM</category><category>PhaaS</category><category>Credential Theft</category></item></channel></rss>