#phaas — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #phaas, aggregated by home.social.
-
#ARToken #PhaaS exposes #EvilTokens' #Microsoft365 #phishing toolkit
-
#ARToken #PhaaS exposes #EvilTokens' #Microsoft365 #phishing toolkit
-
#FBI nimmt #Phishing-as-a-Service-Plattform „#Outsider“ hops | Security https://www.heise.de/news/FBI-nimmt-Phishing-as-a-Service-Plattform-Outsider-hops-11334123.html #OperationGhostHook #OperationRiptide #CyberCrime #PhaaS
-
#FBI nimmt #Phishing-as-a-Service-Plattform „#Outsider“ hops | Security https://www.heise.de/news/FBI-nimmt-Phishing-as-a-Service-Plattform-Outsider-hops-11334123.html #OperationGhostHook #OperationRiptide #CyberCrime #PhaaS
-
📣🚨🪝Group-IB, INTERPOL and Algerian Police have dismantled a decade-old Phishing-as-a-Service (#PhaaS) Network called #SniperDZ, known for providing ready-made login pages to steal credentials. Its alleged developer has been arrested as well.
Read: https://hackread.com/authorities-dismantle-sniperdz-phishing-network/
-
📣🚨🪝Group-IB, INTERPOL and Algerian Police have dismantled a decade-old Phishing-as-a-Service (#PhaaS) Network called #SniperDZ, known for providing ready-made login pages to steal credentials. Its alleged developer has been arrested as well.
Read: https://hackread.com/authorities-dismantle-sniperdz-phishing-network/
-
Kali365-Phishing-Dienst kompromittiert Microsoft 365-Konten durch Umgehung von MFA
Mehr: https://maniabel.work/archiv/1660
#Kali365, #Phishing #MFA #Microsoft365 #OAuth-Token #phishing-as-a-service #PhaaS
#up2date #BeDiS -
Kali365-Phishing-Dienst kompromittiert Microsoft 365-Konten durch Umgehung von MFA
Mehr: https://maniabel.work/archiv/1660
#Kali365, #Phishing #MFA #Microsoft365 #OAuth-Token #phishing-as-a-service #PhaaS
#up2date #BeDiS -
Chinese PhaaS Ecosystem Evolves, Threatens Global Financial Security
The game has changed in the world of phishing: attackers are now using Phishing as a Service (PhaaS) to intercept one-time passcodes and tokenize payment cards, giving them direct control over victims' financial accounts. This sinister shift threatens global financial security, allowing attackers to tap into accounts…
#PhishingAsAService #Phaas #FinancialSecurity #GoogleThreatIntelligenceGroup #Gtig
-
Post 3/3
This isn't new technique -- it traces to Russian state actors in mid-2024. What's new is the commodity layer. EvilTokens as a service in February 2026, 340+ organisations compromised within weeks. Kali365 in April. FBI PSA yesterday. The gap between "state-sponsored" and "Telegram subscription" is now measured in months.
Block device code flow in Entra ID Conditional Access. That's it. It was available before Kali365 existed.
https://haunted.lighthouse.co.im/articles/the-mfa-that-wasnt/
#InfoSec #MFA #PhaaS -
FBI warnt vor PhaaS-Plattform Kali365 – Microsoft-365-Konten im Visier
-
Tycoon2FA-Phishing nutzt 2FA gegen MS365
Seit Ende April 2026 beobachten Sicherheitsexperten eine neue Welle von Phishing-Angriffen, die selbst die Zwei-Faktor-Authentifizierung (MFA) für eigene, kriminelle Zwecke nutzen.
Mehr: https://maniabel.work/archiv/1591
#2FA #Microsoft365 #PhaaS #Phishing #PhishingAsAService #Trustifi
-
📰 CISA Warns of 'ShadowProxy' Phishing-as-a-Service that Bypasses MFA
⚠️ CISA & FBI warn of 'ShadowProxy' Phishing-as-a-Service that bypasses MFA! The platform uses adversary-in-the-middle (AiTM) attacks to steal session cookies for M365/Google accounts. Move to FIDO2 now! #PhaaS #MFA #Phishing #CISA
-
📢⚠️ #Bluekit, a new AI-powered phishing-as-a-service kit, lets attackers bypass MFA using #AiTM attacks and stolen session cookies. With 40+ fake templates and AI tools.
Read: https://hackread.com/bluekit-phishing-kit-targets-platforms-mfa-bypass-attack/
-
📢⚠️ #Bluekit, a new AI-powered phishing-as-a-service kit, lets attackers bypass MFA using #AiTM attacks and stolen session cookies. With 40+ fake templates and AI tools.
Read: https://hackread.com/bluekit-phishing-kit-targets-platforms-mfa-bypass-attack/
-
Фишинг 2025–2026: от социальной инженерии к промышленным конвейерам PhaaS
Современный ландшафт киберугроз демонстрирует окончательную трансформацию фишинга из набора разрозненных мошеннических писем в зрелую сервисную индустрию, функционирующую по канонам легитимного ИТ-бизнеса. Фишинг на протяжении многих лет остается одним из наиболее востребованных способов получения первоначального доступа к корпоративной инфраструктуре, сохраняя свою эффективность вопреки массовому внедрению многофакторной аутентификации (MFA) и инвестициям в антиспам-фильтрацию.
https://habr.com/ru/companies/pt/articles/1020880/
#фишинг #mfa #phaas #парсинг #aitm #dkim #dmark #seg #ocr #вредоносное_по
-
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.
-
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.
-
A phishing-as-a-service platform targeting the trucking and logistics sectors and widely used platforms therein has been disrupted. The Russian and Armenian #PhaaS operators involved displayed deep industry knowledge, which they parlayed into focused fraud campaigns. https://www.databreachtoday.com/phishing-platform-targeting-trucking-logistics-disrupted-a-30846
-
A phishing-as-a-service platform targeting the trucking and logistics sectors and widely used platforms therein has been disrupted. The Russian and Armenian #PhaaS operators involved displayed deep industry knowledge, which they parlayed into focused fraud campaigns. https://www.databreachtoday.com/phishing-platform-targeting-trucking-logistics-disrupted-a-30846
-
(Microsoft) myth: 99.9% of phishing is prevented by using MFA
See also (2019): https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/all-your-creds-are-belong-to-us/ba-p/855124
-
(Microsoft) myth: 99.9% of phishing is prevented by using MFA
See also (2019): https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/all-your-creds-are-belong-to-us/ba-p/855124
-
KrakenBite continues expanding its phishing-as-a-service ecosystem, now offering 115+ bank-themed phishing pages across multiple regions, with new additions targeting Moroccan institutions.
The model includes dashboards, automated purchasing, and support channels - resembling SaaS workflows.How should defenders adjust their monitoring and response strategies in light of increasingly polished PhaaS kits?
Source: https://www.redhotcyber.com/en/post/krakenbite-phishing-service-exposed/
Follow us for ongoing threat intelligence updates.
#Infosec #Cybersecurity #ThreatIntel #Phishing #PhaaS #DigitalSecurity #FraudPrevention #CybercrimeTrends #TechNadu
-
Zwakke 2FA/MFA werkt AVERECHTS
In https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912477 schreef ik eerder deze week:
❝
2FA (MFA) is ruk.Laat de overheid een wachtwoordmanager adviseren die wél op domeinnamen checkt.
❞
(Dat laatste kan standaard onder Android, iOS en iPadOS - middels "AutoFill").Op veler "verzoek" onderbouwde ik die stelling (niet voor de eerste keer) in https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912530.
En in https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912733 legde ik uit waarom online inloggen *lastig* veilig te krijgen is - wat je ook verzint (het blijven shared secrets).
Vandaag heb ik Microsoft Authenticator ook maar weer eens getest (onder Android). Mijn bevindingen leest u in (de tweede helft van) https://www.security.nl/posting/912441/65-plussers+gebruiken+tweestapsverificatie+minder+vaak+dan+gemiddeld#posting912864 - hieronder een stukje daaruit.
#ZwakkeMFA #SMS #AuthenticatorApps #Zwakke2FA #Weak2FA #WeakMFA #MicrosoftAuthenticator #2FAsucks #MFAsucks #Phishing #NepWebsites #PhaaS #Evilginx2 #SIMswap #SS7 #AcountTakeOver #CookieTheft #AccountLockout
-
https://winbuzzer.com/2025/11/12/microsoft-365-users-face-new-automated-phishing-threat-xcxwbn
Microsoft 365 Users Face New Automated Phishing Threat
#Cybersecurity #Phishing #Microsoft365 #InfoSec #CyberAttack #ThreatIntel #PhaaS #Microsoft #EmailSecurity #Cybercrime #DataSecurity #KnowBe4 #Hacking
-
https://winbuzzer.com/2025/11/12/microsoft-365-users-face-new-automated-phishing-threat-xcxwbn
Microsoft 365 Users Face New Automated Phishing Threat
#Cybersecurity #Phishing #Microsoft365 #InfoSec #CyberAttack #ThreatIntel #PhaaS #Microsoft #EmailSecurity #Cybercrime #DataSecurity #KnowBe4 #Hacking
-
Massive Lucid PhaaS Campaign: 17,500 Phishing Domains Mimic 316 Global Brands https://gbhackers.com/lucid-phaas-campaign/ #CyberSecurityNews #cybersecurity #Phishing #PhaaS
-
Massive Lucid PhaaS Campaign: 17,500 Phishing Domains Mimic 316 Global Brands https://gbhackers.com/lucid-phaas-campaign/ #CyberSecurityNews #cybersecurity #Phishing #PhaaS
-
VoidProxy PhaaS Targets Microsoft 365 and Google Accounts in New Campaign https://gbhackers.com/microsoft-365-and-google/ #CyberSecurityNews #cybersecurity #Microsoft #Google #PhaaS
-
VoidProxy PhaaS Targets Microsoft 365 and Google Accounts in New Campaign https://gbhackers.com/microsoft-365-and-google/ #CyberSecurityNews #cybersecurity #Microsoft #Google #PhaaS
-
New VoidProxy Phishing Service Bypasses MFA on Microsoft and Google Accounts https://hackread.com/voidproxy-phishing-service-bypasses-mfa-microsoft-google/ #Cybersecurity #PhishingScam #CyberAttack #Microsoft #VoidProxy #Security #Phishing #security #Google #PhaaS #AitM #Okta #MFA
-
New VoidProxy Phishing Service Bypasses MFA on Microsoft and Google Accounts https://hackread.com/voidproxy-phishing-service-bypasses-mfa-microsoft-google/ #Cybersecurity #PhishingScam #CyberAttack #Microsoft #VoidProxy #Security #Phishing #security #Google #PhaaS #AitM #Okta #MFA
-
De digitale dreigingen nemen in snelheid en complexiteit toe, en een van de meest zorgwekkende aanvallen is Adversary-in-the-Middle (AitM) phishing.
Artikel Cybercrimeinfo: https://www.ccinfo.nl/menu-onderwijs-ontwikkeling/cybercrime/phishing/2557618_wie-zit-er-tussen-jou-en-je-wachtwoord-de-gevaren-van-aitm-phishing-onthuld
Podcast Spotify: https://open.spotify.com/episode/4wUUyfd3JSFFgYbff3KOny?si=054a2c87cbe54176
Podcast Youtube: https://youtu.be/ngli1dXuicc
#AitMphishing #Phishing #Cybercrime #Cybersecurity #PhishingAsAService #PhaaS #ReverseProxy #MFA #MultiFactorAuthentication #BEC #BusinessEmailCompromise #Ransomware #DataProtection
-
🔍 Phishing-as-a-Service (#PhaaS) is driving a wave of large-scale, sophisticated attacks against organisations.
In our new blogpost, we provide an overview of the key techniques, tactics and social engineering schemes that cybercriminals use in AitM phishing attacks.
-
🔍 Phishing-as-a-Service (#PhaaS) is driving a wave of large-scale, sophisticated attacks against organisations.
In our new blogpost, we provide an overview of the key techniques, tactics and social engineering schemes that cybercriminals use in AitM phishing attacks.
-
FBI shared a list of phishing domains associated with the LabHost PhaaS platform – Source: securityaffairs.com https://ciso2ciso.com/fbi-shared-a-list-of-phishing-domains-associated-with-the-labhost-phaas-platform-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #PhishingasaService #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #CyberCrime #Cybercrime #PhaaS
-
FBI shared a list of phishing domains associated with the LabHost PhaaS platform – Source: securityaffairs.com https://ciso2ciso.com/fbi-shared-a-list-of-phishing-domains-associated-with-the-labhost-phaas-platform-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #PhishingasaService #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #CyberCrime #Cybercrime #PhaaS
-
Tycoon2FA phishing kit rolled out significant updates – Source: securityaffairs.com https://ciso2ciso.com/tycoon2fa-phishing-kit-rolled-out-significant-updates-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #Tycoon2FAPhaaS #BreakingNews #SecurityNews #hackingnews #CyberCrime #Cybercrime #Security #hacking #Malware #PhaaS
-
Tycoon2FA phishing kit rolled out significant updates – Source: securityaffairs.com https://ciso2ciso.com/tycoon2fa-phishing-kit-rolled-out-significant-updates-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #Tycoon2FAPhaaS #BreakingNews #SecurityNews #hackingnews #CyberCrime #Cybercrime #Security #hacking #Malware #PhaaS
-
This week, we encountered a new phishing campaign utilizing the Tycoon 2FA Phishing-as-a-Service (PhaaS) to bypass multifactor authentication (MFA).
The RDGA domains have Russian TLDs but are hosted on CloudFlare infrastructure. We have been seeing them use shared infrastructure for a few months now, definitely trying to make detection more challenging. They continue to obfuscate every piece of code but have updated their verification page. Previously, we always saw their custom Cloudflare Turnstile page, but now they also use a new captcha challenge, as shown below.(You can also check it here https://urlscan.io/result/0195ed8b-7a48-7348-a814-0a058571b51e/ )
Their old Cloudflare Turnstile page seems to still be their favorite, even though they now change their message more frequently: "Checking response before request" or "Tracking security across platform" are some of the new messages they use.
Here is a sample of the hundreds of domains we are detecting:
womivor[.]ru
nthecatepi[.]ru
toimlqdo[.]ru
dantherevin[.]ru
xptdieemy[.]ru#dns #domains #phishing #AitM #PhaaS #tycoon #scam #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #2MFABypass
-
This week, we encountered a new phishing campaign utilizing the Tycoon 2FA Phishing-as-a-Service (PhaaS) to bypass multifactor authentication (MFA).
The RDGA domains have Russian TLDs but are hosted on CloudFlare infrastructure. We have been seeing them use shared infrastructure for a few months now, definitely trying to make detection more challenging. They continue to obfuscate every piece of code but have updated their verification page. Previously, we always saw their custom Cloudflare Turnstile page, but now they also use a new captcha challenge, as shown below.(You can also check it here https://urlscan.io/result/0195ed8b-7a48-7348-a814-0a058571b51e/ )
Their old Cloudflare Turnstile page seems to still be their favorite, even though they now change their message more frequently: "Checking response before request" or "Tracking security across platform" are some of the new messages they use.
Here is a sample of the hundreds of domains we are detecting:
womivor[.]ru
nthecatepi[.]ru
toimlqdo[.]ru
dantherevin[.]ru
xptdieemy[.]ru#dns #domains #phishing #AitM #PhaaS #tycoon #scam #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #2MFABypass
-
We published a blog yesterday about a PhaaS and phishing kit that employs DoH and DNS MX records to dynamically serve personalized phishing content. It also uses adtech infrastructure to bypass email security and sends stolen credentials to various data collection spaces, such as Telegram, Discord, and email. https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/
#dns #doh #mx #adtech #obfuscation #phaas #phishing #phishingkit #threatintel #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #wordpress #spam #telegram #discord #morphingmeerkat
-
We published a blog yesterday about a PhaaS and phishing kit that employs DoH and DNS MX records to dynamically serve personalized phishing content. It also uses adtech infrastructure to bypass email security and sends stolen credentials to various data collection spaces, such as Telegram, Discord, and email. https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/
#dns #doh #mx #adtech #obfuscation #phaas #phishing #phishingkit #threatintel #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #wordpress #spam #telegram #discord #morphingmeerkat
-
2025 Phishing Surge: Sneaky 2FA Emerges Alongside Tycoon 2FA and EvilProxy - https://www.redpacketsecurity.com/sneaky-2fa-joins-tycoon-2fa-and-evilproxy-in-2025-phishing-surge/
-
2025 Phishing Surge: Sneaky 2FA Emerges Alongside Tycoon 2FA and EvilProxy - https://www.redpacketsecurity.com/sneaky-2fa-joins-tycoon-2fa-and-evilproxy-in-2025-phishing-surge/
-
Phishing-as-a-service is an area that is increasing rapidly according to research by security vendor Barracuda Networks, which says it has detected a “massive spike” in PhaaS attacks in the first two months of this year.
#phishing #phaas #tycoon2fa #evilproxy #infosec #cybersecurity #barracuda #technews
-
Phishing-as-a-service is an area that is increasing rapidly according to research by security vendor Barracuda Networks, which says it has detected a “massive spike” in PhaaS attacks in the first two months of this year.
#phishing #phaas #tycoon2fa #evilproxy #infosec #cybersecurity #barracuda #technews
-
The new Darcula phishing-as-a-service (PhaaS) platform lets cybercriminals clone any brand’s website and create phishing pages in minutes—no coding skills required. In the past year, 95,000 phishing domains and 31,000 IP addresses have been linked to #Darcula.
Using this suite, attackers can submit a URL to generate a clone, then select the HTML elements to replace and inject phishing content (e.g., payment forms and login fields) to create a malicious replica of the legitimate landing page. They can then use the admin panel to manage their phishing campaigns and data collection.
It's getting harder to spot these attacks, so make sure you are training your team to carefully inspect URLs and email addresses, and enter known URLs rather than clicking links. Please contact us if you need help setting up a training program for your team.
Read about Darcula: https://thehackernews.com/2025/02/cybercriminals-can-now-clone-any-brands.html
#Cybersecurity #Phishing #PhaaS #Infosec #IT #DFIR #CISO #ITsecurity #training #cyberaware #SMB
-
Phishing-as-a-Service Rockstar 2FA continues to be prevalent – Source: securityaffairs.com https://ciso2ciso.com/phishing-as-a-service-rockstar-2fa-continues-to-be-prevalent-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #PhishingasaService #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #Rockstar2FA #CyberCrime #Cybercrime #Phishing #hacking #PhaaS