Skip to main content
← All Articles

Tag

#PhaaS

11 articles

Advertisement

JWR Phishing Framework: Real-time Data Theft via PhaaS
HIGH
Malware

JWR Phishing Framework: Real-time Data Theft via PhaaS

The JWR phishing framework, a variant of The Outsider PhaaS, harvests payment data, PII, and 2FA codes in real-time via operator-controlled sessions.

Runtime Rebel Intel
4 min read · Aug 13, 2026
Greatness PhaaS Adds Device Code Phishing for MFA Bypass
HIGH
Threat Intel

Greatness PhaaS Adds Device Code Phishing for MFA Bypass

Greatness PhaaS now supports device code phishing, abusing OAuth 2.0 to bypass MFA and seize accounts on Microsoft 365, Google Workspace, and more.

Runtime Rebel Intel
5 min read · Aug 4, 2026
Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks
MEDIUM
Threat Intel

Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks

Forg365 PhaaS enables attackers to compromise Microsoft 365 accounts using AI-assisted lures and device code phishing to bypass multi-factor authentication.

Runtime Rebel Intel
3 min read · Jul 13, 2026
HIGH
Threat Intel

Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise

Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing.

Runtime Rebel Intel
4 min read · Jul 9, 2026
MEDIUM
Threat Intel

ARToken PhaaS Exposes EvilTokens' M365 Phishing Toolkit

ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.

Runtime Rebel Intel
5 min read · Jul 3, 2026
Chinese Smishing Network 'Outsider' Leverages Gemini AI for Phishing
HIGH
Threat Intel

Chinese Smishing Network 'Outsider' Leverages Gemini AI for Phishing

Google sues a Chinese smishing network operating 'Outsider' PhaaS, accused of using Gemini AI to craft sophisticated phishing messages targeting Americans.

Runtime Rebel Intel
5 min read · Jun 12, 2026

Advertisement

HIGH
Threat Intel

FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts

The FBI issues an advisory on Kali365, a Phishing-as-a-Service platform exploiting OAuth device code flows to bypass MFA and hijack Microsoft 365 accounts.

Runtime Rebel Intel
3 min read · May 25, 2026
MEDIUM
Threat Intel

Chinese-Language PhaaS: Real-Time OTP Interception and Tokenization

Chinese-language PhaaS providers like Darcula are shifting to real-time OTP interception and digital wallet tokenization to bypass modern MFA controls.

Runtime Rebel Intel
4 min read · May 25, 2026
EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow
HIGH
Threat Intel

EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow

The EvilTokens platform has compromised 340+ Microsoft 365 organizations by weaponizing OAuth Device Code Flows to bypass multi-factor authentication.

Runtime Rebel Intel
4 min read · May 19, 2026
HIGH
Threat Intel

VENOM PhaaS: New Phishing Attacks Target Senior Executives' Microsoft Logins

Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.

Runtime Rebel Intel
4 min read · Apr 10, 2026
HIGH
Threat Intel

Starkiller Phishing-as-a-Service: Technical Analysis of Adversary-in-the-Middle Frameworks

An examination of the Starkiller phishing platform, which employs transparent reverse proxy techniques to relay authentication traffic and capture multi-factor…

Runtime Rebel Intel
2 min read · Feb 23, 2026