Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Top 10 Phishing Kits Used by Threat Actors in Cyberattacks
July 28, 2026
Critical JetBrains TeamCity CVE-2024-27198 Flaw Lets Attackers Run OS Commands
July 28, 2026
Chrome Extension Spies on AI Conversations in ChatGPT, Claude, Gemini
July 28, 2026
Home/CyberSecurity News/Top 10 Phishing Kits Used by Threat Actors in Cyberattacks
CyberSecurity News

Top 10 Phishing Kits Used by Threat Actors in Cyberattacks

Key Takeaways Sophisticated Phishing-as-a-Service (PhaaS) kits continue to pose a significant threat, leveraging advanced techniques like MFA bypass and AI-driven impersonation. Microsoft 365...

Sarah simpson
Sarah simpson
July 28, 2026 6 Min Read
3 0

Key Takeaways

  • Sophisticated Phishing-as-a-Service (PhaaS) kits continue to pose a significant threat, leveraging advanced techniques like MFA bypass and AI-driven impersonation.
  • Microsoft 365 environments remain a prime target, with attackers exploiting OAuth device-code flows and session-cookie vulnerabilities.
  • Despite law enforcement disruptions, kits like Kratos and Tycoon2FA show residual activity, indicating a resilient and adaptable threat landscape.

PhaaS Kits Dominate Cyberattack Landscape with Advanced Evasion Techniques

The cybersecurity landscape continues to grapple with a persistent onslaught of sophisticated phishing attacks, largely fueled by readily available Phishing-as-a-Service (PhaaS) kits. These platforms enable threat actors to execute highly convincing campaigns, often bypassing multi-factor authentication (MFA) and leveraging advanced techniques to evade detection. Recent activity highlights a dynamic environment where new kits emerge, and even disrupted services show enduring operational presence.

Table Of Content

  • Key Takeaways
  • PhaaS Kits Dominate Cyberattack Landscape with Advanced Evasion Techniques
  • Weekly Threat Activity Snapshot
  • Prominent Phishing Kits in Circulation
  • Greatness: Microsoft 365 Specialist
  • Kratos: Resilient Despite Takedown
  • Tycoon2FA: Adapting to Disruption
  • Cephas: Evasive and Obfuscated
  • Known Infection Vectors (Cross-Kit Summary)
  • Known Tools Used by Attackers
  • Targeted Industries
  • Common Vulnerabilities and Weaknesses Exploited
  • Full List of Indicators of Compromise (IOCs)
  • Domains and URLs
  • File Paths and Endpoints
  • IP Addresses
  • Behavioral/Detection Indicators
  • MITRE ATT&CK Mapping
  • What You Should Do

Weekly Threat Activity Snapshot

Analysis of recent threat data reveals a shifting focus in attack vectors. OAuth flow phishing remains a significant concern, with 2,446 uploads and a weekly increase of 194 instances. Quishing (QR code phishing) incidents totaled 974 uploads, showing a slight decrease of 17. PDF-based lures were observed in 536 uploads, decreasing by 111, while malicious URLs accounted for 229 uploads, down by 67. The cybercriminal group Storm-1747 was linked to 50 uploads, a reduction of 6.

Common infection vectors consistently involve malicious email links and attachments, typical of commodity PhaaS distribution. These campaigns utilize templated login-page cloning and credential-exfiltration backends. Targets span various sectors, reflecting the mass-distribution nature of PhaaS campaigns, with vulnerabilities primarily focused on credential and session-token harvesting via cloned authentication pages.

Prominent Phishing Kits in Circulation

Greatness: Microsoft 365 Specialist

Active since November 2022, Greatness is a mature PhaaS offering primarily targeting Microsoft 365 users. This kit includes MFA bypass capabilities, IP filtering, and Telegram bot integration for real-time notifications. Its effectiveness stems from pre-filling victim email addresses and dynamically injecting legitimate company logos and background images, making phishing pages highly credible for business users.

Campaigns leveraging Greatness predominantly target manufacturing, healthcare, and technology sectors across the US, UK, Australia, South Africa, and Canada. Attackers use phishing emails with attachment or link builders to generate deceptive decoy and login pages. The kit employs an API-driven structure and a TOTP-capturing proxy to circumvent MFA through man-in-the-middle attacks against Microsoft 365 authentication.

Kratos: Resilient Despite Takedown

The Kratos PhaaS operation faced a significant disruption in July 2026, when German (BKA/ZIT) and US law enforcement agencies seized over 200 servers and apprehended its alleged Indonesian developer. Investigators estimated that Kratos served approximately 1,800 paying customers who launched around 15,000 campaigns monthly. Despite this takedown, residual activity persists, with 76 uploads observed this week, a decrease of 4, indicating that the kit’s code remains accessible to cybercriminals. Kratos was adept at harvesting both credentials and session cookies, effectively neutralizing MFA defenses.

Infection vectors commonly involved phishing pages mimicking Microsoft 365 login interfaces, frequently delivered through Business Email Compromise (BEC)-style lures. Kratos utilized an AiTM proxy, leaving forensic signatures such as login pages loading “barr.svg” and “lg.svg” assets, and posting stolen data to “next.php” or “save.php” endpoints. Its primary targets were global enterprise organizations, with a strong focus on BEC for financial fraud. The kit exploited session-cookie theft to bypass MFA and capitalized on organizations’ lack of monitoring for AiTM proxy signatures.

Tycoon2FA: Adapting to Disruption

Tycoon2FA, operated by the threat actor Storm-1747, previously dominated the global AiTM PhaaS market. At its peak in 2025, it was responsible for an estimated 44.5% of all credential-theft attacks and 89% of the AiTM PhaaS market. A law enforcement disruption in 2026 reduced its footprint, and this week’s observed decrease of 11 uploads reflects a continued decline. However, as noted by Barracuda, the ecosystem has largely redistributed rather than disappeared entirely.

This kit uses fake CAPTCHA-gated phishing pages and Microsoft/Gmail login clones, distributed via phishing emails. Tycoon2FA relies on a reverse-proxy AiTM server, abuses Cloudflare Turnstile CAPTCHA for anti-bot evasion, and incorporates JavaScript fingerprinting, geofencing, and Telegram for real-time alerts. It targets defense, manufacturing, insurance, and technology sectors globally, exploiting real-time session-cookie/token capture post-MFA and OAuth app-consent grant abuse.

Cephas: Evasive and Obfuscated

First identified in August 2024, Cephas is an obfuscated AiTM kit designed to evade detection. It embeds random invisible characters and incorporates astronomy/bible-themed code comments, specifically to bypass YARA-rule and pattern-based detection mechanisms. Cephas directly validates stolen credentials and session tokens against Microsoft APIs during submission. This week, it recorded the sharpest decline among named kits, with 27 uploads, a drop of 79.

Attack campaigns utilizing Cephas often begin with business-inquiry-themed phishing emails that lead to downloads from file-sharing platforms. The kit employs anti-bot/anti-analysis obfuscation, Microsoft API credential validation, and has been observed using steganographic payload delivery in related campaigns. It targets cross-sector Microsoft 365 environments, exploiting static/pattern-based scanner evasion and using credential/token validation to bypass fraud-detection heuristics.

Known Infection Vectors (Cross-Kit Summary)

  • Device-code phishing lures, often disguised as document-share, calendar-invite, or SharePoint-access notifications.
  • QR-code (“quishing”) embedded in fraudulent invoice or payment-receipt PDFs, currently accounting for 974 weekly uploads.
  • Fake CAPTCHA-gated landing pages that precede redirects to credential-harvesting sites.
  • Compromised legitimate platforms used as initial senders or URL redirectors, frequently coupled with multi-layered link-rewriter chains.
  • Business-inquiry emails prompting downloads from legitimate file-sharing services, containing obfuscated JavaScript and other malicious scripts.

Known Tools Used by Attackers

  • Telegram bots for real-time credential alerts, command and control (C2), and the distribution or sale of PhaaS kits.
  • AiTM reverse-proxy frameworks, including variations of Evilginx2, Muraena, and Modlishka.
  • Automation scripts designed to exploit OAuth 2.0 device-authorization grants.
  • Modules for abusing Cloudflare Turnstile and other CAPTCHA services to bypass anti-bot defenses.
  • Browser-in-the-browser (BitB) techniques to create convincing fake login overlays.
  • Code obfuscation methods, such as invisible Unicode characters and steganographic image payloads.

Targeted Industries

Industry Kits Observed Targeting It
Finance & Insurance EvilTokens, Tycoon2FA, Kratos
Manufacturing Greatness, Tycoon2FA
Healthcare Greatness
Technology / SaaS Sneaky2FA, Evilginx2/EvilProxy, Tycoon2FA
Government / Defense Tycoon2FA
HR, Logistics, Sales (functional targeting) EvilTokens

Common Vulnerabilities and Weaknesses Exploited

  • Unrestricted OAuth device-code authorization flow within Microsoft Entra ID tenants, which is a primary enabler for kits like EvilTokens, Kali365, and Tycoon2FA’s newer device-code module.
  • Session-cookie/token replay after legitimate MFA completion, effectively bypassing SMS, push, and TOTP-based second factors.
  • Authentication-state transfer between devices, if left unrestricted in Entra ID, exploited by Kali365.
  • Lack of Conditional Access scoping on device-code, geolocation, and device-compliance signals.
  • Absence of phishing-resistant MFA (FIDO2/WebAuthn/passkeys), leaving OTP/push-based MFA vulnerable to AiTM interception.
  • Weak anti-phishing pattern detection, bypassed by obfuscation techniques like Cephas’s invisible-character embedding and Sneaky2FA’s browser-in-the-browser rendering.

Full List of Indicators of Compromise (IOCs)

Domains and URLs

Indicator Associated Kit
authdocspro[.]com EvilTokens
backdoor-hub[.]com EvilTokens
bumpgames[.]net EvilTokens
carbatterygurgaon[.]com EvilTokens
careldutoit-el[.]co[.]za EvilTokens
dao[.]com[.]au EvilTokens
docusend[.]net EvilTokens
ssolutionmail[.]com EvilTokens
eqfit[.]co[.]za EvilTokens
eventcalender-schedule[.]com EvilTokens
evobothub[.]org EvilTokens
m365-verification[.]ru Tycoon2FA
authportal-gmail[.]org Tycoon2FA
tycoonkit-login[.]su Tycoon2FA
evilproxy[.]pro EvilProxy
top-cyber[.]club EvilProxy
rproxy[.]io / login-live.rproxy[.]io EvilProxy
msdnmail[.]net EvilProxy
dwbud[.]vilaribit[.]com Kratos-family kit
api[.]telegram[.]org (exfil endpoint) Multiple PhaaS kits (Telegram C2)
geoplugin[.]net (victim geolocation) Kratos-family kit

File Paths and Endpoints

Indicator Associated Kit
/cllascio.php Tycoon2FA
/PTT/SOft Kratos-family kit
next.php, save.php (credential POST endpoints) Kratos
barr.svg, lg.svg (paired login-page assets, 90% detection recall) Kratos

IP Addresses

Indicator Associated Kit
147[.]78[.]47[.]250 EvilProxy
185[.]158[.]251[.]169 EvilProxy
194[.]76[.]226[.]166 EvilProxy
185.231.204.77 Tycoon2FA
193.124.182.69 Tycoon2FA
41.128.0.142 (Egypt-based relay origin) Kratos-family kit

Behavioral/Detection Indicators

  • Impossible device shifts: inconsistent User-Agent strings observed across authentication steps within a single session (e.g., Sneaky2FA).
  • Device-code sign-ins originating from unfamiliar devices, unusual geographical locations, or accounts that typically do not utilize device-code flow.
  • The creation of new or modification of existing inbox rules (e.g., auto-delete, external forwarding, move-to-RSS-Feeds) following an account compromise.
  • Mass Microsoft Graph API mailbox reads or bulk searches that are inconsistent with established baseline user behavior.
  • Unexpected OAuth application consent grants identified in tenant audit logs.
  • Phishing subject-line template patterns such as “Notice of charge – [6-digit number]” or lures themed around DocuSign.

MITRE ATT&CK Mapping

  • T1566 (Phishing): Initial access gained through document or invoice-themed lures, observed across all nine kits.
  • T1557 (Adversary-in-the-Middle): A core technique employed by Sneaky2FA, Evilginx2/EvilProxy, Tycoon2FA, Kratos, Greatness, and Cephas.
  • T1567 (Exfiltration Over Web Service): The Telegram Bot API is frequently used for credential and session exfiltration.
  • T1550.001 (Use of Application Access Token): OAuth token abuse is central to EvilTokens and Kali365 device-code campaigns.

What You Should Do

  • Restrict or disable OAuth device-code flow within Microsoft Entra ID via Conditional Access policies, unless it is explicitly required for specific IoT or CLI workflows.
  • Deploy phishing-resistant MFA, such as FIDO2/WebAuthn or passkeys, for all users, with a priority on privileged accounts. This cryptographically binds authentication to the legitimate origin, effectively defeating classic AiTM relay attacks.
  • Actively monitor sign-in and Graph API logs for any anomalous device-code usage, mass mailbox reads, or the creation of new inbox rules.
  • Regularly audit OAuth app consent grants to identify and revoke any unauthorized token issuance before lateral movement or BEC can occur.
  • Immediately revoke sessions and refresh tokens upon any suspicion of compromise, and treat unsolicited device-code requests as inherently suspicious, regardless of the perceived legitimacy of the hosting page.
  • Integrate the provided IOCs into email gateways, web proxies, and SIEM detection rules. Further enrich these with threat intelligence platforms like ANY.RUN TI Lookup for real-time correlation against emerging phishing infrastructure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitphishingThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical JetBrains TeamCity CVE-2024-27198 Flaw Lets Attackers Run OS Commands

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Origin Confirms Data Breach Exposing 900,000 Customer Records
July 28, 2026
Critical Apache Shiro RCE Vulnerability Under Active Exploitation
July 28, 2026
Google Ads Push MacSync Infostealer via Fake Claude Install Guides
July 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us