<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Phishing as a Service</title><description>Cybersecurity articles tagged #Phishing as a Service on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>BigBear PhaaS Bypasses Microsoft 365 MFA at 258 Orgs</title><link>https://runtimerebel.com/blog/bigbear-phaas-bypasses-microsoft-365-mfa-at-258-orgs</link><guid isPermaLink="true">https://runtimerebel.com/blog/bigbear-phaas-bypasses-microsoft-365-mfa-at-258-orgs</guid><description>BigBear 2.0 PhaaS uses Evilginx2 AiTM to bypass Microsoft 365 MFA, stealing credentials and session cookies from 258 organizations.</description><pubDate>Tue, 08 Sep 2026 02:04:22 GMT</pubDate><category>BigBear</category><category>Microsoft 365</category><category>MFA Bypass</category><category>Phishing as a Service</category><category>AitM</category></item><item><title>iAuthFlow V2 Phishing Toolkit Leverages Passkeys for Persistence</title><link>https://runtimerebel.com/blog/iauthflow-v2-phishing-toolkit-leverages-passkeys-for-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/iauthflow-v2-phishing-toolkit-leverages-passkeys-for-persistence</guid><description>Discover how the iAuthFlow V2 phishing toolkit registers malicious passkeys to maintain persistent account access despite password resets.</description><pubDate>Sun, 23 Aug 2026 00:44:48 GMT</pubDate><category>Phishing</category><category>Credential Theft</category><category>Passkeys</category><category>Phishing as a Service</category></item><item><title>Dismantling Kratos: Law Enforcement Disrupts Phishing-as-a-Service Hub</title><link>https://runtimerebel.com/blog/dismantling-kratos-law-enforcement-disrupts-phishing-as-a-service-hub</link><guid isPermaLink="true">https://runtimerebel.com/blog/dismantling-kratos-law-enforcement-disrupts-phishing-as-a-service-hub</guid><description>Law enforcement agencies dismantle the Kratos PhaaS platform, arresting its developer and disrupting infrastructure used for high-scale session cookie theft.</description><pubDate>Wed, 22 Jul 2026 02:46:13 GMT</pubDate><category>Kratos PhaaS</category><category>AitM</category><category>Phishing as a Service</category><category>Cybercrime Takedown</category><category>Credential Theft</category></item><item><title>Forg365 PhaaS Leverages AI, AiTM for Microsoft 365 Account Compromise</title><link>https://runtimerebel.com/blog/forg365-phaas-leverages-ai-aitm-for-microsoft-365-account-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/forg365-phaas-leverages-ai-aitm-for-microsoft-365-account-compromise</guid><description>Forg365 PhaaS targets Microsoft 365 with AI-assisted AiTM and device code phishing.</description><pubDate>Thu, 09 Jul 2026 15:14:50 GMT</pubDate><category>Forg365</category><category>Phishing as a Service</category><category>PhaaS</category><category>Microsoft 365</category><category>AitM</category><category>AI Phishing</category><category>Device Code Phishing</category></item><item><title>Google Sues Outsider Enterprise Over Gemini-Powered Phishing-as-a-Service</title><link>https://runtimerebel.com/blog/google-sues-outsider-enterprise-over-gemini-powered-phishing-as-a-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-sues-outsider-enterprise-over-gemini-powered-phishing-as-a-service</guid><description>Google takes legal action against Outsider Enterprise, a Chinese cybercrime network using Gemini AI to automate sophisticated phishing campaigns against global users.</description><pubDate>Tue, 07 Jul 2026 11:11:04 GMT</pubDate><category>Outsider Enterprise</category><category>Phishing as a Service</category><category>Gemini AI</category><category>Google</category><category>Scams</category><category>Cybercrime</category></item><item><title>FBI and Google Dismantle Outsider Enterprise Phishing Service</title><link>https://runtimerebel.com/blog/fbi-and-google-dismantle-outsider-enterprise-phishing-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-and-google-dismantle-outsider-enterprise-phishing-service</guid><description>Law enforcement and Google disrupt Outsider Enterprise, a massive Phishing-as-a-Service platform responsible for $1.9 billion in losses.</description><pubDate>Mon, 15 Jun 2026 10:15:24 GMT</pubDate><category>Outsider Enterprise</category><category>Phishing as a Service</category><category>FBI</category><category>Google</category><category>Financial Crime</category></item><item><title>Sniper Dz Phishing-as-a-Service Targets MENA Region via Facebook</title><link>https://runtimerebel.com/blog/sniper-dz-phishing-as-a-service-targets-mena-region-via-facebook</link><guid isPermaLink="true">https://runtimerebel.com/blog/sniper-dz-phishing-as-a-service-targets-mena-region-via-facebook</guid><description>Sniper Dz phishing campaigns leverage fake Facebook accounts and browser alerts to steal credentials from users across the Middle East and North Africa.</description><pubDate>Mon, 15 Jun 2026 10:14:07 GMT</pubDate><category>Sniper Dz</category><category>Phishing as a Service</category><category>MENA Region</category><category>Social Engineering</category><category>Facebook Scams</category></item><item><title>FBI Disrupts AI-Powered Outsider Enterprise PhaaS Operation</title><link>https://runtimerebel.com/blog/fbi-disrupts-ai-powered-outsider-enterprise-phaas-operation</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-disrupts-ai-powered-outsider-enterprise-phaas-operation</guid><description>The FBI, Google, and Black Lotus Labs dismantled Outsider Enterprise, a Chinese-based AI-powered phishing service that deployed over a million malicious URLs.</description><pubDate>Sun, 14 Jun 2026 16:36:57 GMT</pubDate><category>Outsider Enterprise</category><category>Phishing as a Service</category><category>FBI Takedown</category><category>Credential Theft</category><category>AI Phishing</category></item><item><title>Chinese Smishing Network &apos;Outsider&apos; Leverages Gemini AI for Phishing</title><link>https://runtimerebel.com/blog/chinese-smishing-network-outsider-leverages-gemini-ai-for-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-smishing-network-outsider-leverages-gemini-ai-for-phishing</guid><description>Google sues a Chinese smishing network operating &apos;Outsider&apos; PhaaS, accused of using Gemini AI to craft sophisticated phishing messages targeting Americans.</description><pubDate>Fri, 12 Jun 2026 20:51:49 GMT</pubDate><category>Smishing</category><category>Phishing as a Service</category><category>PhaaS</category><category>Outsider</category><category>Gemini AI</category><category>Google</category><category>Cybercrime Network</category><category>China</category><category>Social Engineering</category></item><item><title>Kali365 Phishing-as-a-Service Expands to Target AWS and Okta</title><link>https://runtimerebel.com/blog/kali365-phishing-as-a-service-expands-to-target-aws-and-okta</link><guid isPermaLink="true">https://runtimerebel.com/blog/kali365-phishing-as-a-service-expands-to-target-aws-and-okta</guid><description>The FBI-flagged Kali365 phishing kit now targets AWS and Okta via device code phishing, bypassing multi-factor authentication for cloud enterprise accounts.</description><pubDate>Wed, 03 Jun 2026 05:44:29 GMT</pubDate><category>Kali365</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>Cloud Security</category><category>AWS</category><category>Okta</category></item><item><title>Tycoon2FA Phishing Kit Targets Microsoft 365 via Device Code Flow</title><link>https://runtimerebel.com/blog/tycoon2fa-phishing-kit-targets-microsoft-365-via-device-code-flow</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon2fa-phishing-kit-targets-microsoft-365-via-device-code-flow</guid><description>Tycoon2FA phishing kit now leverages Microsoft 365 device code flows and Trustifi URL abuse to bypass MFA and hijack enterprise accounts.</description><pubDate>Sun, 17 May 2026 16:26:13 GMT</pubDate><category>Tycoon 2FA</category><category>Microsoft 365</category><category>Phishing as a Service</category><category>Device Code Flow</category></item><item><title>Tycoon 2FA Market Shift: Fragmentation and the Rise of Dadsec</title><link>https://runtimerebel.com/blog/tycoon-2fa-market-shift-fragmentation-and-the-rise-of-dadsec</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-market-shift-fragmentation-and-the-rise-of-dadsec</guid><description>Analysis of Tycoon 2FA&apos;s declining market share as threat actors reuse its technical artifacts in Dadsec and other phishing-as-a-service platforms.</description><pubDate>Sat, 18 Apr 2026 12:18:24 GMT</pubDate><category>Tycoon 2FA</category><category>Dadsec</category><category>Phishing as a Service</category><category>AitM</category><category>MFA Bypass</category></item><item><title>VENOM PhaaS: New Phishing Attacks Target Senior Executives&apos; Microsoft Logins</title><link>https://runtimerebel.com/blog/venom-phaas-new-phishing-attacks-target-senior-executives-microsoft-logins</link><guid isPermaLink="true">https://runtimerebel.com/blog/venom-phaas-new-phishing-attacks-target-senior-executives-microsoft-logins</guid><description>Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.</description><pubDate>Fri, 10 Apr 2026 05:03:44 GMT</pubDate><category>VENOM</category><category>Phishing as a Service</category><category>PhaaS</category><category>Credential Theft</category><category>Microsoft Logins</category><category>C Suite</category><category>Executive Phishing</category></item><item><title>Tycoon 2FA PaaS Recovery: Detecting AitM Phishing Infrastructure</title><link>https://runtimerebel.com/blog/tycoon-2fa-paas-recovery-detecting-aitm-phishing-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-paas-recovery-detecting-aitm-phishing-infrastructure</guid><description>Tycoon 2FA Phishing-as-a-Service has recovered from law enforcement disruption. Learn how this AitM platform bypasses MFA and how to protect your organization.</description><pubDate>Mon, 23 Mar 2026 12:24:24 GMT</pubDate><category>Tycoon 2FA</category><category>AitM</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>Credential Theft</category></item><item><title>Europol Dismantles Tycoon 2FA Phishing Platform: Mitigating MFA Bypass</title><link>https://runtimerebel.com/blog/europol-dismantles-tycoon-2fa-phishing-platform-mitigating-mfa-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/europol-dismantles-tycoon-2fa-phishing-platform-mitigating-mfa-bypass</guid><description>Europol and cybersecurity vendors dismantle Tycoon 2FA, a major phishing-as-a-service platform known for its sophisticated MFA bypass capabilities.</description><pubDate>Fri, 06 Mar 2026 00:40:08 GMT</pubDate><category>Tycoon 2FA</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>Europol</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Tycoon 2FA PhaaS Infrastructure Dismantled in Europol-Led Operation</title><link>https://runtimerebel.com/blog/tycoon-2fa-phaas-infrastructure-dismantled-in-europol-led-operation</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-phaas-infrastructure-dismantled-in-europol-led-operation</guid><description>Europol and global law enforcement dismantle Tycoon 2FA, a Phishing-as-a-Service kit used in 64,000 attacks to bypass MFA via AitM techniques.</description><pubDate>Thu, 05 Mar 2026 08:16:06 GMT</pubDate><category>Tycoon 2FA</category><category>Europol</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>AitM</category></item><item><title>Tycoon 2FA PhaaS Platform Dismantled in Global Law Enforcement Takedown</title><link>https://runtimerebel.com/blog/tycoon-2fa-phaas-platform-dismantled-in-global-law-enforcement-takedown</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-2fa-phaas-platform-dismantled-in-global-law-enforcement-takedown</guid><description>International law enforcement dismantled Tycoon 2FA, a Phishing-as-a-Service platform used to bypass MFA and target 500,000 organizations monthly.</description><pubDate>Wed, 04 Mar 2026 20:15:37 GMT</pubDate><category>Tycoon 2FA</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>AitM</category><category>Europol</category></item></channel></rss>