<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #PhaaS</title><description>Cybersecurity articles tagged #PhaaS on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>JWR Phishing Framework: Real-time Data Theft via PhaaS</title><link>https://runtimerebel.com/blog/jwr-phishing-framework-real-time-data-theft-via-phaas</link><guid isPermaLink="true">https://runtimerebel.com/blog/jwr-phishing-framework-real-time-data-theft-via-phaas</guid><description>The JWR phishing framework, a variant of The Outsider PhaaS, harvests payment data, PII, and 2FA codes in real-time via operator-controlled sessions.</description><pubDate>Thu, 13 Aug 2026 16:47:48 GMT</pubDate><category>Phishing</category><category>PhaaS</category><category>Credential Theft</category><category>PII</category><category>JWR</category></item><item><title>Greatness PhaaS Adds Device Code Phishing for MFA Bypass</title><link>https://runtimerebel.com/blog/greatness-phaas-adds-device-code-phishing-for-mfa-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/greatness-phaas-adds-device-code-phishing-for-mfa-bypass</guid><description>Greatness PhaaS now supports device code phishing, abusing OAuth 2.0 to bypass MFA and seize accounts on Microsoft 365, Google Workspace, and more.</description><pubDate>Tue, 04 Aug 2026 17:30:11 GMT</pubDate><category>PhaaS</category><category>MFA Bypass</category><category>OAuth 2 0</category><category>Microsoft 365</category><category>Greatness</category></item><item><title>Forg365 PhaaS: Bypassing MFA in Microsoft 365 via AitM Attacks</title><link>https://runtimerebel.com/blog/forg365-phaas-bypassing-mfa-in-microsoft-365-via-aitm-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/forg365-phaas-bypassing-mfa-in-microsoft-365-via-aitm-attacks</guid><description>Forg365 PhaaS enables attackers to compromise Microsoft 365 accounts using AI-assisted lures and device code phishing to bypass multi-factor authentication.</description><pubDate>Mon, 13 Jul 2026 14:38:14 GMT</pubDate><category>Forg365</category><category>Microsoft 365</category><category>PhaaS</category><category>AitM</category><category>Device Code Phishing</category></item><item><title>Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise</title><link>https://runtimerebel.com/blog/forg365-phaas-leverages-ai-aitm-for-microsoft-365-account-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/forg365-phaas-leverages-ai-aitm-for-microsoft-365-account-compromise</guid><description>Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing.</description><pubDate>Thu, 09 Jul 2026 15:14:50 GMT</pubDate><category>Forg365</category><category>Phishing as a Service</category><category>PhaaS</category><category>Microsoft 365</category><category>AitM</category><category>AI Phishing</category><category>Device Code Phishing</category></item><item><title>ARToken PhaaS Exposes EvilTokens&apos; M365 Phishing Toolkit</title><link>https://runtimerebel.com/blog/artoken-phaas-exposes-eviltokens-m365-phishing-toolkit</link><guid isPermaLink="true">https://runtimerebel.com/blog/artoken-phaas-exposes-eviltokens-m365-phishing-toolkit</guid><description>ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.</description><pubDate>Fri, 03 Jul 2026 17:28:05 GMT</pubDate><category>ARToken</category><category>EvilTokens</category><category>PhaaS</category><category>Phishing</category><category>Microsoft 365</category><category>MFA Bypass</category><category>Credential Harvesting</category><category>Threat Intelligence</category></item><item><title>Chinese Smishing Network &apos;Outsider&apos; Leverages Gemini AI for Phishing</title><link>https://runtimerebel.com/blog/chinese-smishing-network-outsider-leverages-gemini-ai-for-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-smishing-network-outsider-leverages-gemini-ai-for-phishing</guid><description>Google sues a Chinese smishing network operating &apos;Outsider&apos; PhaaS, accused of using Gemini AI to craft sophisticated phishing messages targeting Americans.</description><pubDate>Fri, 12 Jun 2026 20:51:49 GMT</pubDate><category>Smishing</category><category>Phishing as a Service</category><category>PhaaS</category><category>Outsider</category><category>Gemini AI</category><category>Google</category><category>Cybercrime Network</category><category>China</category><category>Social Engineering</category></item><item><title>FBI Warns of Kali365 PhaaS Targeting Microsoft 365 Accounts</title><link>https://runtimerebel.com/blog/fbi-warns-of-kali365-phaas-targeting-microsoft-365-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warns-of-kali365-phaas-targeting-microsoft-365-accounts</guid><description>The FBI issues an advisory on Kali365, a Phishing-as-a-Service platform exploiting OAuth device code flows to bypass MFA and hijack Microsoft 365 accounts.</description><pubDate>Mon, 25 May 2026 13:18:04 GMT</pubDate><category>Kali365</category><category>Microsoft 365</category><category>PhaaS</category><category>Oauth Abuse</category><category>MFA Bypass</category></item><item><title>Chinese-Language PhaaS: Real-Time OTP Interception and Tokenization</title><link>https://runtimerebel.com/blog/chinese-language-phaas-real-time-otp-interception-and-tokenization</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-language-phaas-real-time-otp-interception-and-tokenization</guid><description>Chinese-language PhaaS providers like Darcula are shifting to real-time OTP interception and digital wallet tokenization to bypass modern MFA controls.</description><pubDate>Mon, 25 May 2026 05:38:17 GMT</pubDate><category>PhaaS</category><category>UNC5814</category><category>Darcula</category><category>MFA Bypass</category><category>Tokenization</category><category>YY Lai Yu</category></item><item><title>EvilTokens PhaaS: Bypassing MFA via OAuth Device Code Flow</title><link>https://runtimerebel.com/blog/eviltokens-phaas-bypassing-mfa-via-oauth-device-code-flow</link><guid isPermaLink="true">https://runtimerebel.com/blog/eviltokens-phaas-bypassing-mfa-via-oauth-device-code-flow</guid><description>The EvilTokens platform has compromised 340+ Microsoft 365 organizations by weaponizing OAuth Device Code Flows to bypass multi-factor authentication.</description><pubDate>Tue, 19 May 2026 13:15:26 GMT</pubDate><category>EvilTokens</category><category>Microsoft 365</category><category>Oauth Phishing</category><category>Device Code Flow</category><category>PhaaS</category></item><item><title>VENOM PhaaS: New Phishing Attacks Target Senior Executives&apos; Microsoft Logins</title><link>https://runtimerebel.com/blog/venom-phaas-new-phishing-attacks-target-senior-executives-microsoft-logins</link><guid isPermaLink="true">https://runtimerebel.com/blog/venom-phaas-new-phishing-attacks-target-senior-executives-microsoft-logins</guid><description>Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.</description><pubDate>Fri, 10 Apr 2026 05:03:44 GMT</pubDate><category>VENOM</category><category>Phishing as a Service</category><category>PhaaS</category><category>Credential Theft</category><category>Microsoft Logins</category><category>C Suite</category><category>Executive Phishing</category></item><item><title>Starkiller Phishing-as-a-Service: Technical Analysis of Adversary-in-the-Middle Frameworks</title><link>https://runtimerebel.com/blog/starkiller-phishing-as-a-service-technical-analysis-of-adversary-in-the-middle-frameworks</link><guid isPermaLink="true">https://runtimerebel.com/blog/starkiller-phishing-as-a-service-technical-analysis-of-adversary-in-the-middle-frameworks</guid><description>An examination of the Starkiller phishing platform, which employs transparent reverse proxy techniques to relay authentication traffic and capture multi-factor…</description><pubDate>Mon, 23 Feb 2026 08:20:40 GMT</pubDate><category>Phishing</category><category>MFA Bypass</category><category>AitM</category><category>PhaaS</category><category>Credential Theft</category></item></channel></rss>