Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026, driven overwhelmingly by OAuth device-code flow abuse and adversary-in-the-middle (AiTM) kits targeting Microsoft 365 identities.
Cybercriminal group Storm-1747, the operator behind Tycoon2FA, logged 50 attributed uploads, down 6 from the prior week following ongoing law-enforcement pressure on its infrastructure.
The data below is sourced from ANY.RUN’s weekly Threat Intelligence Lookup snapshot and cross-referenced against vendor research from Microsoft, Sekoia, Push Security, Barracuda, and The Hacker News.
Weekly Activity Snapshot
CategoryTotal UploadsWeekly ChangeOAuth Flow Phishing2,446+194Suspected Quishing (QR phishing)974-17PDF-based lures536-111Malicious URLs229-67Storm-1747 (cybercriminal group)50-6
The rise in OAuth flow phishing (+194) confirms that device-code authentication abuse has overtaken classic credential-harvesting pages as the primary AiTM technique this week, a trend flagged repeatedly by Microsoft, Push Security, and LevelBlue through Q2-Q3 2026.
Top 10 Phishing Kits Ranked by Weekly Activity
RankKit NameTotal UploadsWeekly ChangePrimary Technique1Sneaky2FA886-303AiTM reverse proxy, Telegram PhaaS2EvilTokens684+65OAuth device-code phishing3Evilginx2/EvilProxy660-199Reverse-proxy AiTM, cookie theft4Kali365503+17Device-code token theft5MassBass90-19Emerging PhaaS credential harvester6Greatness88+30M365 AiTM proxy, MFA/TOTP bypass7Kratos76-4AiTM session-cookie theft (post-takedown remnants)8Tycoon2FA46-11AiTM reverse proxy, Storm-17479Cephas27-79Obfuscated anti-bot AiTM kit
Nine named kits are tracked individually in the source data; “OAuth Flow Phishing” and “Suspected Quishing” are broader technique categories that overlap with several of the kits above, particularly EvilTokens and Kali365.
Top 10 Phishing Kits
Detailed Kit Profiles
1. Sneaky2FA 886 uploads (-303)
Sneaky2FA is a full-featured, Telegram-sold PhaaS platform first detected in October 2024 that specifically compromises Microsoft 365 accounts via AiTM reverse-proxy interception.
It validates stolen credentials in real time against legitimate Microsoft APIs, uses blurred screenshots of real Microsoft interfaces as decoy backgrounds, and employs browser-in-the-browser fake login windows to defeat sandbox detection.
Despite the largest weekly decline of any kit (-303), it remains the single most-used phishing kit this week.
Infection Vector: Phishing emails with fake payment receipts containing QR codes linking to spoofed Microsoft 365 login pages
Tools Used: Telegram-based PhaaS panel, AiTM reverse proxy, browser-in-the-browser overlay
Targeted Industries: Enterprise Microsoft 365 tenants across finance, professional services, and technology
Vulnerabilities Exploited: OTP/TOTP-based MFA bypass via session token relay; inconsistent User-Agent strings across auth steps reveal “impossible device shifts”
2. EvilTokens 684 uploads (+65)
EvilTokens is a rapidly growing PhaaS kit that abuses the OAuth 2.0 device authorization grant flow, letting attackers hijack a legitimate, MFA-verified Microsoft 365 login without ever touching a password.
Delivered through Telegram bots, it bundles token harvesting, email harvesting, reconnaissance, and AI-driven lure generation, and has already been used in a March 2026 campaign against more than 340 organizations.
Its recon phase runs 10-15 days ahead of the actual phishing attempt, making early detection critical.
Infection Vector: Emails disguised as invoices, shared documents, calendar invites, or SharePoint access requests urging victims to “Verify to view”
Tools Used: Telegram bot C2, OAuth device-code request automation, AI-driven lure generation
Targeted Industries: Finance, HR, logistics, and sales departments within Microsoft 365 enterprise tenants
Vulnerabilities Exploited: OAuth 2.0 device authorization grant flow abuse; no Conditional Access restriction on device-code sign-ins
3. Evilginx2 / EvilProxy 660 uploads (-199)
Evilginx2 is an open-source, red-team-turned-criminal reverse-proxy framework, while EvilProxy is its commercialized PhaaS derivative sold from $150-$400/month on dark web forums.
Both intercept live traffic between victims and real identity providers (Microsoft 365, Okta, Google Workspace) to harvest session cookies post-MFA.
Infection Vector: Phishing links directing victims to attacker-controlled reverse-proxy domains that mirror real login pages
Tools Used: Evilginx2/Modlishka/Muraena-style reverse proxy, cookie injection modules, dark-web subscription panels
Targeted Industries: Fortune 500 enterprises, SaaS and cloud-service consumers globally
Vulnerabilities Exploited: Session-cookie replay after legitimate MFA completion; lack of FIDO2-bound authentication
4. Kali365 503 uploads (+17)
Kali365, first observed in April 2026 and subject to an FBI advisory, is a subscription PhaaS kit (US$250/month or US$2,000/year) that steals Microsoft 365 access tokens via device-code phishing, entirely bypassing password entry and MFA prompts.
Victims approve what looks like a document-share or Teams-invite code on a genuine Microsoft URL, unknowingly authorizing the attacker’s session.
Infection Vector: Fake document-share/Teams-invite messages instructing victims to enter a device code at a real Microsoft URL
Tools Used: Telegram promotion channel, device-code flow automation, persistent OAuth token harvesting
Targeted Industries: Broad enterprise and SMB Microsoft 365 users; shared conference-room/IoT device abuse also observed
Vulnerabilities Exploited: Unrestricted device-code authorization grant flow; authentication-state transfer between devices
5. MassBass 90 uploads (-19)
MassBass is tracked by ANY.RUN as an emerging phishing-kit family within the current AiTM/PhaaS wave; while public vendor writeups are limited compared to the larger kits, its inclusion in this week’s top-10 by upload volume indicates active criminal adoption for credential and session harvesting.
Infection Vector: Malicious email links and attachments consistent with commodity PhaaS distribution patterns
Tools Used: Templated login-page cloning, credential-exfiltration backend typical of PhaaS kits
Targeted Industries: Cross-sector, consistent with mass-distribution PhaaS campaigns
Vulnerabilities Exploited: Credential and session-token harvesting via cloned authentication pages
6. Greatness 88 uploads (+30)
Active since November 2022, Greatness is a mature PhaaS tool with MFA bypass, IP filtering, and Telegram bot integration, focused exclusively on Microsoft 365 phishing pages.
It pre-fills the victim’s email address and injects the target company’s real logo and background, making it especially convincing for business users.
Campaigns concentrate on manufacturing, healthcare, and technology firms in the US, UK, Australia, South Africa, and Canada.
Infection Vector: Phishing emails with attachment/link builder generating decoy and login pages
Tools Used: API-driven phishing kit, Telegram bot notifications, TOTP-capturing proxy
Targeted Industries: Manufacturing, healthcare, and technology sectors across five countries
Vulnerabilities Exploited: TOTP/MFA bypass via man-in-the-middle proxying of Microsoft 365 authentication
7. Kratos 76 uploads (-4)
Kratos was dismantled by German (BKA/ZIT) and US law enforcement in July 2026, with over 200 servers seized and its alleged Indonesian developer arrested; investigators estimate 1,800 paying customers ran roughly 15,000 monthly campaigns.
Despite the takedown, residual activity (76 uploads, -4) persists because the kit code remains in criminal hands. Kratos harvested both credentials and session cookies, defeating MFA entirely.
Infection Vector: Phishing pages mimicking Microsoft 365 login, often via BEC-style lures
Tools Used: AiTM proxy; forensic signature includes login pages loading barr.svg and lg.svg assets, posting stolen data to next.php or save.php endpoints
Targeted Industries: Global enterprise organizations, heavy BEC use for financial fraud
Vulnerabilities Exploited: Session-cookie theft enabling MFA bypass; lack of monitoring for AiTM proxy signatures
8. Tycoon2FA 46 uploads (-11)
Tycoon2FA, operated by threat actor Storm-1747, has been the dominant global AiTM PhaaS platform since August 2023, at its peak responsible for an estimated 44.5% of all credential-theft attacks and 89% of the AiTM PhaaS market in 2025.
A 2026 law-enforcement disruption reduced its footprint, and this week’s -11 change reflects continued decay, though Barracuda notes the ecosystem has redistributed rather than disappeared.
Infection Vector: Fake CAPTCHA-gated phishing pages and Microsoft/Gmail login clones distributed via phishing email
Tools Used: Reverse-proxy AiTM server, Cloudflare Turnstile CAPTCHA abuse, JavaScript fingerprinting, geofencing, Telegram real-time alerting
Targeted Industries: Defense, manufacturing, insurance, and technology sectors globally
Vulnerabilities Exploited: Real-time session-cookie/token capture post-MFA; OAuth app-consent grant abuse
9. Cephas 27 uploads (-79)
Cephas, first seen in August 2024, is an obfuscated AiTM kit notable for embedding random invisible characters and astronomy/bible-themed code comments to evade YARA-rule and pattern-based detection.
It validates stolen credentials and session tokens directly against Microsoft APIs during submission and logged the sharpest weekly drop (-79) among named kits this week.
Infection Vector: Business-inquiry-themed phishing emails leading to file-sharing platform downloads
Tools Used: Anti-bot/anti-analysis obfuscation, Microsoft API credential validation, steganographic payload delivery in related campaigns
Targeted Industries: Cross-sector Microsoft 365 environments
Vulnerabilities Exploited: Static/pattern-based scanner evasion; credential/token validation bypasses fraud-detection heuristics
Known Infection Vectors (Cross-Kit Summary)
Device-code phishing lures disguised as document-share, calendar-invite, or SharePoint-access notifications
QR-code (“quishing”) embedded in fake invoice/payment-receipt PDFs, now 974 weekly uploads
Fake CAPTCHA-gated landing pages preceding credential-harvesting redirects
Compromised legitimate platforms abused as senders or URL redirectors, plus multi-layered link-rewriter chains
Business-inquiry emails driving downloads from legitimate file-sharing services carrying obfuscated JavaScript and malicious scripts
Known Tools Used by Attackers
Telegram bots for real-time credential alerts, C2, and PhaaS kit distribution/sales
AiTM reverse-proxy frameworks (Evilginx2, Muraena, Modlishka lineage)
OAuth 2.0 device-authorization-grant automation scripts
Cloudflare Turnstile and other CAPTCHA-abuse modules for anti-bot evasion
Browser-in-the-browser (BitB) fake login overlays
Code obfuscation via invisible Unicode characters and steganographic image payloads
Targeted Industries
IndustryKits Observed Targeting ItFinance & InsuranceEvilTokens, Tycoon2FA, KratosManufacturingGreatness, Tycoon2FAHealthcareGreatnessTechnology / SaaSSneaky2FA, Evilginx2/EvilProxy, Tycoon2FAGovernment / DefenseTycoon2FAHR, Logistics, Sales (functional targeting)EvilTokens
Common Vulnerabilities and Weaknesses Exploited
Unrestricted OAuth device-code authorization flow in Microsoft Entra ID tenants, the single biggest enabler behind EvilTokens, Kali365, and Tycoon2FA’s newer device-code module
Session-cookie/token replay after legitimate MFA completion, defeating SMS, push, and TOTP-based second factors
Authentication-state transfer between devices left unrestricted in Entra ID, exploited by Kali365
Lack of Conditional Access scoping on device-code, geolocation, and device-compliance signals
Absent phishing-resistant MFA (FIDO2/WebAuthn/passkeys), leaving OTP/push-based MFA vulnerable to AiTM interception
Weak anti-phishing pattern detection, bypassed by Cephas’s invisible-character obfuscation and Sneaky2FA’s browser-in-the-browser rendering
Full List of Indicators of Compromise (IOCs)
Domains and URLs
IndicatorAssociated Kitauthdocspro[.]comEvilTokensbackdoor-hub[.]comEvilTokensbumpgames[.]netEvilTokenscarbatterygurgaon[.]comEvilTokenscareldutoit-el[.]co[.]zaEvilTokensdao[.]com[.]auEvilTokensdocusend[.]netEvilTokensssolutionmail[.]comEvilTokenseqfit[.]co[.]zaEvilTokenseventcalender-schedule[.]comEvilTokensevobothub[.]orgEvilTokensm365-verification[.]ruTycoon2FAauthportal-gmail[.]orgTycoon2FAtycoonkit-login[.]suTycoon2FAevilproxy[.]proEvilProxytop-cyber[.]clubEvilProxyrproxy[.]io / login-live.rproxy[.]ioEvilProxymsdnmail[.]netEvilProxydwbud[.]vilaribit[.]comKratos-family kitapi[.]telegram[.]org (exfil endpoint)Multiple PhaaS kits (Telegram C2)geoplugin[.]net (victim geolocation)Kratos-family kit
File Paths and Endpoints
IndicatorAssociated Kit/cllascio.phpTycoon2FA/PTT/SOftKratos-family kitnext.php, save.php (credential POST endpoints)Kratosbarr.svg, lg.svg (paired login-page assets, 90% detection recall)Kratos
IP Addresses
IndicatorAssociated Kit147[.]78[.]47[.]250EvilProxy185[.]158[.]251[.]169EvilProxy194[.]76[.]226[.]166EvilProxy185.231.204.77Tycoon2FA193.124.182.69Tycoon2FA41.128.0.142 (Egypt-based relay origin)Kratos-family kit
Behavioral/Detection Indicators
Impossible device shifts: inconsistent User-Agent strings across authentication steps within a single session (Sneaky2FA)
Device-code sign-ins from unfamiliar devices, unusual geographies, or accounts that don’t normally use device-code flow
New or modified inbox rules (auto-delete, external forwarding, move-to-RSS-Feeds) following account compromise
Mass Microsoft Graph API mailbox reads/bulk searches inconsistent with baseline user behavior
Unexpected OAuth application consent grants in tenant audit logs
Phishing subject-line template pattern: “Notice of charge – [6-digit number]” / DocuSign-themed lures
MITRE ATT&CK Mapping
T1566 (Phishing): Initial access via document/invoice-themed lures across all nine kits
T1557 (Adversary-in-the-Middle): Core technique for Sneaky2FA, Evilginx2/EvilProxy, Tycoon2FA, Kratos, Greatness, Cephas
T1567 (Exfiltration Over Web Service): Telegram Bot API used for credential/session exfiltration
T1550.001 (Use of Application Access Token): OAuth token abuse central to EvilTokens and Kali365 device-code campaigns
Defensive Recommendations for SOC Teams
Restrict or disable OAuth device-code flow in Microsoft Entra ID via Conditional Access unless explicitly required by IoT/CLI workflows
Deploy phishing-resistant MFA (FIDO2/WebAuthn, passkeys) for all users, prioritizing privileged accounts, since it cryptographically binds authentication to the legitimate origin and defeats classic AiTM relay
Monitor sign-in and Graph API logs for anomalous device-code usage, mass mailbox reads, and new inbox-rule creation
Audit OAuth app consent grants regularly to catch unauthorized token issuance before lateral movement or BEC occurs
Revoke sessions and refresh tokens immediately upon suspected compromise, and treat unsolicited device-code requests as inherently suspicious regardless of the legitimacy of the hosting page
Feed the IOCs above into email gateways, web proxies, and SIEM detection rules, and enrich with threat intelligence platforms such as ANY.RUN TI Lookup for real-time correlation against new phishing infrastructure
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) appeared first on Cyber Security News.


