Advertisement
BigBear PhaaS Bypasses Microsoft 365 MFA at 258 Orgs
BigBear 2.0 PhaaS uses Evilginx2 AiTM to bypass Microsoft 365 MFA, stealing credentials and session cookies from 258 organizations.
iAuthFlow V2 Phishing Toolkit Leverages Passkeys for Persistence
Discover how the iAuthFlow V2 phishing toolkit registers malicious passkeys to maintain persistent account access despite password resets.
Dismantling Kratos: Law Enforcement Disrupts Phishing-as-a-Service Hub
Law enforcement agencies dismantle the Kratos PhaaS platform, arresting its developer and disrupting infrastructure used for high-scale session cookie theft.
Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise
Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing.
Google Sues Outsider Enterprise Over Gemini-Powered Phishing-as-a-Service
Google takes legal action against Outsider Enterprise, a Chinese cybercrime network using Gemini AI to automate sophisticated phishing campaigns against global users.
FBI and Google Dismantle Outsider Enterprise Phishing Service
Law enforcement and Google disrupt Outsider Enterprise, a massive Phishing-as-a-Service platform responsible for $1.9 billion in losses.
Advertisement
Sniper Dz Phishing-as-a-Service Targets MENA Region via Facebook
Sniper Dz phishing campaigns leverage fake Facebook accounts and browser alerts to steal credentials from users across the Middle East and North Africa.
FBI Disrupts AI-Powered Outsider Enterprise PhaaS Operation
The FBI, Google, and Black Lotus Labs dismantled Outsider Enterprise, a Chinese-based AI-powered phishing service that deployed over a million malicious URLs.
Chinese Smishing Network 'Outsider' Leverages Gemini AI for Phishing
Google sues a Chinese smishing network operating 'Outsider' PhaaS, accused of using Gemini AI to craft sophisticated phishing messages targeting Americans.
Kali365 Phishing-as-a-Service Expands to Target AWS and Okta
The FBI-flagged Kali365 phishing kit now targets AWS and Okta via device code phishing, bypassing multi-factor authentication for cloud enterprise accounts.
Tycoon2FA Phishing Kit Targets Microsoft 365 via Device Code Flow
Tycoon2FA phishing kit now leverages Microsoft 365 device code flows and Trustifi URL abuse to bypass MFA and hijack enterprise accounts.
Tycoon 2FA Market Shift: Fragmentation and the Rise of Dadsec
Analysis of Tycoon 2FA's declining market share as threat actors reuse its technical artifacts in Dadsec and other phishing-as-a-service platforms.
VENOM PhaaS: New Phishing Attacks Target Senior Executives' Microsoft Logins
Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.
Tycoon 2FA PaaS Recovery: Detecting AitM Phishing Infrastructure
Tycoon 2FA Phishing-as-a-Service has recovered from law enforcement disruption. Learn how this AitM platform bypasses MFA and how to protect your organization.
Europol Dismantles Tycoon 2FA Phishing Platform: Mitigating MFA Bypass
Europol and cybersecurity vendors dismantle Tycoon 2FA, a major phishing-as-a-service platform known for its sophisticated MFA bypass capabilities.
Tycoon 2FA PhaaS Infrastructure Dismantled in Europol-Led Operation
Europol and global law enforcement dismantle Tycoon 2FA, a Phishing-as-a-Service kit used in 64,000 attacks to bypass MFA via AitM techniques.
Tycoon 2FA PhaaS Platform Dismantled in Global Law Enforcement Takedown
International law enforcement dismantled Tycoon 2FA, a Phishing-as-a-Service platform used to bypass MFA and target 500,000 organizations monthly.