Top 10 Phishing Kits Used by Threat Actors in Cyberattacks
Key Takeaways Sophisticated Phishing-as-a-Service (PhaaS) kits continue to pose a significant threat, leveraging advanced techniques like MFA bypass and AI-driven impersonation. Microsoft 365...
Key Takeaways
- Sophisticated Phishing-as-a-Service (PhaaS) kits continue to pose a significant threat, leveraging advanced techniques like MFA bypass and AI-driven impersonation.
- Microsoft 365 environments remain a prime target, with attackers exploiting OAuth device-code flows and session-cookie vulnerabilities.
- Despite law enforcement disruptions, kits like Kratos and Tycoon2FA show residual activity, indicating a resilient and adaptable threat landscape.
PhaaS Kits Dominate Cyberattack Landscape with Advanced Evasion Techniques
The cybersecurity landscape continues to grapple with a persistent onslaught of sophisticated phishing attacks, largely fueled by readily available Phishing-as-a-Service (PhaaS) kits. These platforms enable threat actors to execute highly convincing campaigns, often bypassing multi-factor authentication (MFA) and leveraging advanced techniques to evade detection. Recent activity highlights a dynamic environment where new kits emerge, and even disrupted services show enduring operational presence.
Table Of Content
- Key Takeaways
- PhaaS Kits Dominate Cyberattack Landscape with Advanced Evasion Techniques
- Weekly Threat Activity Snapshot
- Prominent Phishing Kits in Circulation
- Greatness: Microsoft 365 Specialist
- Kratos: Resilient Despite Takedown
- Tycoon2FA: Adapting to Disruption
- Cephas: Evasive and Obfuscated
- Known Infection Vectors (Cross-Kit Summary)
- Known Tools Used by Attackers
- Targeted Industries
- Common Vulnerabilities and Weaknesses Exploited
- Full List of Indicators of Compromise (IOCs)
- Domains and URLs
- File Paths and Endpoints
- IP Addresses
- Behavioral/Detection Indicators
- MITRE ATT&CK Mapping
- What You Should Do
Weekly Threat Activity Snapshot
Analysis of recent threat data reveals a shifting focus in attack vectors. OAuth flow phishing remains a significant concern, with 2,446 uploads and a weekly increase of 194 instances. Quishing (QR code phishing) incidents totaled 974 uploads, showing a slight decrease of 17. PDF-based lures were observed in 536 uploads, decreasing by 111, while malicious URLs accounted for 229 uploads, down by 67. The cybercriminal group Storm-1747 was linked to 50 uploads, a reduction of 6.
Common infection vectors consistently involve malicious email links and attachments, typical of commodity PhaaS distribution. These campaigns utilize templated login-page cloning and credential-exfiltration backends. Targets span various sectors, reflecting the mass-distribution nature of PhaaS campaigns, with vulnerabilities primarily focused on credential and session-token harvesting via cloned authentication pages.
Prominent Phishing Kits in Circulation
Greatness: Microsoft 365 Specialist
Active since November 2022, Greatness is a mature PhaaS offering primarily targeting Microsoft 365 users. This kit includes MFA bypass capabilities, IP filtering, and Telegram bot integration for real-time notifications. Its effectiveness stems from pre-filling victim email addresses and dynamically injecting legitimate company logos and background images, making phishing pages highly credible for business users.
Campaigns leveraging Greatness predominantly target manufacturing, healthcare, and technology sectors across the US, UK, Australia, South Africa, and Canada. Attackers use phishing emails with attachment or link builders to generate deceptive decoy and login pages. The kit employs an API-driven structure and a TOTP-capturing proxy to circumvent MFA through man-in-the-middle attacks against Microsoft 365 authentication.
Kratos: Resilient Despite Takedown
The Kratos PhaaS operation faced a significant disruption in July 2026, when German (BKA/ZIT) and US law enforcement agencies seized over 200 servers and apprehended its alleged Indonesian developer. Investigators estimated that Kratos served approximately 1,800 paying customers who launched around 15,000 campaigns monthly. Despite this takedown, residual activity persists, with 76 uploads observed this week, a decrease of 4, indicating that the kit’s code remains accessible to cybercriminals. Kratos was adept at harvesting both credentials and session cookies, effectively neutralizing MFA defenses.
Infection vectors commonly involved phishing pages mimicking Microsoft 365 login interfaces, frequently delivered through Business Email Compromise (BEC)-style lures. Kratos utilized an AiTM proxy, leaving forensic signatures such as login pages loading “barr.svg” and “lg.svg” assets, and posting stolen data to “next.php” or “save.php” endpoints. Its primary targets were global enterprise organizations, with a strong focus on BEC for financial fraud. The kit exploited session-cookie theft to bypass MFA and capitalized on organizations’ lack of monitoring for AiTM proxy signatures.
Tycoon2FA: Adapting to Disruption
Tycoon2FA, operated by the threat actor Storm-1747, previously dominated the global AiTM PhaaS market. At its peak in 2025, it was responsible for an estimated 44.5% of all credential-theft attacks and 89% of the AiTM PhaaS market. A law enforcement disruption in 2026 reduced its footprint, and this week’s observed decrease of 11 uploads reflects a continued decline. However, as noted by Barracuda, the ecosystem has largely redistributed rather than disappeared entirely.
This kit uses fake CAPTCHA-gated phishing pages and Microsoft/Gmail login clones, distributed via phishing emails. Tycoon2FA relies on a reverse-proxy AiTM server, abuses Cloudflare Turnstile CAPTCHA for anti-bot evasion, and incorporates JavaScript fingerprinting, geofencing, and Telegram for real-time alerts. It targets defense, manufacturing, insurance, and technology sectors globally, exploiting real-time session-cookie/token capture post-MFA and OAuth app-consent grant abuse.
Cephas: Evasive and Obfuscated
First identified in August 2024, Cephas is an obfuscated AiTM kit designed to evade detection. It embeds random invisible characters and incorporates astronomy/bible-themed code comments, specifically to bypass YARA-rule and pattern-based detection mechanisms. Cephas directly validates stolen credentials and session tokens against Microsoft APIs during submission. This week, it recorded the sharpest decline among named kits, with 27 uploads, a drop of 79.
Attack campaigns utilizing Cephas often begin with business-inquiry-themed phishing emails that lead to downloads from file-sharing platforms. The kit employs anti-bot/anti-analysis obfuscation, Microsoft API credential validation, and has been observed using steganographic payload delivery in related campaigns. It targets cross-sector Microsoft 365 environments, exploiting static/pattern-based scanner evasion and using credential/token validation to bypass fraud-detection heuristics.
Known Infection Vectors (Cross-Kit Summary)
- Device-code phishing lures, often disguised as document-share, calendar-invite, or SharePoint-access notifications.
- QR-code (“quishing”) embedded in fraudulent invoice or payment-receipt PDFs, currently accounting for 974 weekly uploads.
- Fake CAPTCHA-gated landing pages that precede redirects to credential-harvesting sites.
- Compromised legitimate platforms used as initial senders or URL redirectors, frequently coupled with multi-layered link-rewriter chains.
- Business-inquiry emails prompting downloads from legitimate file-sharing services, containing obfuscated JavaScript and other malicious scripts.
Known Tools Used by Attackers
- Telegram bots for real-time credential alerts, command and control (C2), and the distribution or sale of PhaaS kits.
- AiTM reverse-proxy frameworks, including variations of Evilginx2, Muraena, and Modlishka.
- Automation scripts designed to exploit OAuth 2.0 device-authorization grants.
- Modules for abusing Cloudflare Turnstile and other CAPTCHA services to bypass anti-bot defenses.
- Browser-in-the-browser (BitB) techniques to create convincing fake login overlays.
- Code obfuscation methods, such as invisible Unicode characters and steganographic image payloads.
Targeted Industries
| Industry | Kits Observed Targeting It |
| Finance & Insurance | EvilTokens, Tycoon2FA, Kratos |
| Manufacturing | Greatness, Tycoon2FA |
| Healthcare | Greatness |
| Technology / SaaS | Sneaky2FA, Evilginx2/EvilProxy, Tycoon2FA |
| Government / Defense | Tycoon2FA |
| HR, Logistics, Sales (functional targeting) | EvilTokens |
Common Vulnerabilities and Weaknesses Exploited
- Unrestricted OAuth device-code authorization flow within Microsoft Entra ID tenants, which is a primary enabler for kits like EvilTokens, Kali365, and Tycoon2FA’s newer device-code module.
- Session-cookie/token replay after legitimate MFA completion, effectively bypassing SMS, push, and TOTP-based second factors.
- Authentication-state transfer between devices, if left unrestricted in Entra ID, exploited by Kali365.
- Lack of Conditional Access scoping on device-code, geolocation, and device-compliance signals.
- Absence of phishing-resistant MFA (FIDO2/WebAuthn/passkeys), leaving OTP/push-based MFA vulnerable to AiTM interception.
- Weak anti-phishing pattern detection, bypassed by obfuscation techniques like Cephas’s invisible-character embedding and Sneaky2FA’s browser-in-the-browser rendering.
Full List of Indicators of Compromise (IOCs)
Domains and URLs
| Indicator | Associated Kit |
| authdocspro[.]com | EvilTokens |
| backdoor-hub[.]com | EvilTokens |
| bumpgames[.]net | EvilTokens |
| carbatterygurgaon[.]com | EvilTokens |
| careldutoit-el[.]co[.]za | EvilTokens |
| dao[.]com[.]au | EvilTokens |
| docusend[.]net | EvilTokens |
| ssolutionmail[.]com | EvilTokens |
| eqfit[.]co[.]za | EvilTokens |
| eventcalender-schedule[.]com | EvilTokens |
| evobothub[.]org | EvilTokens |
| m365-verification[.]ru | Tycoon2FA |
| authportal-gmail[.]org | Tycoon2FA |
| tycoonkit-login[.]su | Tycoon2FA |
| evilproxy[.]pro | EvilProxy |
| top-cyber[.]club | EvilProxy |
| rproxy[.]io / login-live.rproxy[.]io | EvilProxy |
| msdnmail[.]net | EvilProxy |
| dwbud[.]vilaribit[.]com | Kratos-family kit |
| api[.]telegram[.]org (exfil endpoint) | Multiple PhaaS kits (Telegram C2) |
| geoplugin[.]net (victim geolocation) | Kratos-family kit |
File Paths and Endpoints
| Indicator | Associated Kit |
| /cllascio.php | Tycoon2FA |
| /PTT/SOft | Kratos-family kit |
| next.php, save.php (credential POST endpoints) | Kratos |
| barr.svg, lg.svg (paired login-page assets, 90% detection recall) | Kratos |
IP Addresses
| Indicator | Associated Kit |
| 147[.]78[.]47[.]250 | EvilProxy |
| 185[.]158[.]251[.]169 | EvilProxy |
| 194[.]76[.]226[.]166 | EvilProxy |
| 185.231.204.77 | Tycoon2FA |
| 193.124.182.69 | Tycoon2FA |
| 41.128.0.142 (Egypt-based relay origin) | Kratos-family kit |
Behavioral/Detection Indicators
- Impossible device shifts: inconsistent User-Agent strings observed across authentication steps within a single session (e.g., Sneaky2FA).
- Device-code sign-ins originating from unfamiliar devices, unusual geographical locations, or accounts that typically do not utilize device-code flow.
- The creation of new or modification of existing inbox rules (e.g., auto-delete, external forwarding, move-to-RSS-Feeds) following an account compromise.
- Mass Microsoft Graph API mailbox reads or bulk searches that are inconsistent with established baseline user behavior.
- Unexpected OAuth application consent grants identified in tenant audit logs.
- Phishing subject-line template patterns such as “Notice of charge – [6-digit number]” or lures themed around DocuSign.
MITRE ATT&CK Mapping
- T1566 (Phishing): Initial access gained through document or invoice-themed lures, observed across all nine kits.
- T1557 (Adversary-in-the-Middle): A core technique employed by Sneaky2FA, Evilginx2/EvilProxy, Tycoon2FA, Kratos, Greatness, and Cephas.
- T1567 (Exfiltration Over Web Service): The Telegram Bot API is frequently used for credential and session exfiltration.
- T1550.001 (Use of Application Access Token): OAuth token abuse is central to EvilTokens and Kali365 device-code campaigns.
What You Should Do
- Restrict or disable OAuth device-code flow within Microsoft Entra ID via Conditional Access policies, unless it is explicitly required for specific IoT or CLI workflows.
- Deploy phishing-resistant MFA, such as FIDO2/WebAuthn or passkeys, for all users, with a priority on privileged accounts. This cryptographically binds authentication to the legitimate origin, effectively defeating classic AiTM relay attacks.
- Actively monitor sign-in and Graph API logs for any anomalous device-code usage, mass mailbox reads, or the creation of new inbox rules.
- Regularly audit OAuth app consent grants to identify and revoke any unauthorized token issuance before lateral movement or BEC can occur.
- Immediately revoke sessions and refresh tokens upon any suspicion of compromise, and treat unsolicited device-code requests as inherently suspicious, regardless of the perceived legitimacy of the hosting page.
- Integrate the provided IOCs into email gateways, web proxies, and SIEM detection rules. Further enrich these with threat intelligence platforms like ANY.RUN TI Lookup for real-time correlation against emerging phishing infrastructure.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.