home.social

#phaas — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #phaas, aggregated by home.social.

fetched live
  1. 📣🚨🪝Group-IB, INTERPOL and Algerian Police have dismantled a decade-old Phishing-as-a-Service (#PhaaS) Network called #SniperDZ, known for providing ready-made login pages to steal credentials. Its alleged developer has been arrested as well.

    Read: hackread.com/authorities-disma

    #CyberSecurity #CyberCrime #Phishing #Algeria #Interpol

  2. 📣🚨🪝Group-IB, INTERPOL and Algerian Police have dismantled a decade-old Phishing-as-a-Service (#PhaaS) Network called #SniperDZ, known for providing ready-made login pages to steal credentials. Its alleged developer has been arrested as well.

    Read: hackread.com/authorities-disma

    #CyberSecurity #CyberCrime #Phishing #Algeria #Interpol

  3. Chinese PhaaS Ecosystem Evolves, Threatens Global Financial Security

    The game has changed in the world of phishing: attackers are now using Phishing as a Service (PhaaS) to intercept one-time passcodes and tokenize payment cards, giving them direct control over victims' financial accounts. This sinister shift threatens global financial security, allowing attackers to tap into accounts…

    osintsights.com/chinese-phaas-

    #PhishingAsAService #Phaas #FinancialSecurity #GoogleThreatIntelligenceGroup #Gtig

  4. Post 3/3
    This isn't new technique -- it traces to Russian state actors in mid-2024. What's new is the commodity layer. EvilTokens as a service in February 2026, 340+ organisations compromised within weeks. Kali365 in April. FBI PSA yesterday. The gap between "state-sponsored" and "Telegram subscription" is now measured in months.
    Block device code flow in Entra ID Conditional Access. That's it. It was available before Kali365 existed.
    haunted.lighthouse.co.im/artic
    #InfoSec #MFA #PhaaS

  5. Tycoon2FA-Phishing nutzt 2FA gegen MS365

    Seit Ende April 2026 beobachten Sicherheitsexperten eine neue Welle von Phishing-Angriffen, die selbst die Zwei-Faktor-Authentifizierung (MFA) für eigene, kriminelle Zwecke nutzen.

    Mehr: maniabel.work/archiv/1591

    #2FA #Microsoft365 #PhaaS #Phishing #PhishingAsAService #Trustifi

  6. 📰 CISA Warns of 'ShadowProxy' Phishing-as-a-Service that Bypasses MFA

    ⚠️ CISA & FBI warn of 'ShadowProxy' Phishing-as-a-Service that bypasses MFA! The platform uses adversary-in-the-middle (AiTM) attacks to steal session cookies for M365/Google accounts. Move to FIDO2 now! #PhaaS #MFA #Phishing #CISA

    🔗 cyber.netsecops.io

  7. 📢⚠️ #Bluekit, a new AI-powered phishing-as-a-service kit, lets attackers bypass MFA using #AiTM attacks and stolen session cookies. With 40+ fake templates and AI tools.

    Read: hackread.com/bluekit-phishing-

    #Cybersecurity #Phishing #MFA #AI #Hacking #PhaaS

  8. 📢⚠️ #Bluekit, a new AI-powered phishing-as-a-service kit, lets attackers bypass MFA using #AiTM attacks and stolen session cookies. With 40+ fake templates and AI tools.

    Read: hackread.com/bluekit-phishing-

    #Cybersecurity #Phishing #MFA #AI #Hacking #PhaaS

  9. Фишинг 2025–2026: от социальной инженерии к промышленным конвейерам PhaaS

    Современный ландшафт киберугроз демонстрирует окончательную трансформацию фишинга из набора разрозненных мошеннических писем в зрелую сервисную индустрию, функционирующую по канонам легитимного ИТ-бизнеса. Фишинг на протяжении многих лет остается одним из наиболее востребованных способов получения первоначального доступа к корпоративной инфраструктуре, сохраняя свою эффективность вопреки массовому внедрению многофакторной аутентификации (MFA) и инвестициям в антиспам-фильтрацию.

    habr.com/ru/companies/pt/artic

    #фишинг #mfa #phaas #парсинг #aitm #dkim #dmark #seg #ocr #вредоносное_по

  10. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  11. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  12. A phishing-as-a-service platform targeting the trucking and logistics sectors and widely used platforms therein has been disrupted. The Russian and Armenian #PhaaS operators involved displayed deep industry knowledge, which they parlayed into focused fraud campaigns. databreachtoday.com/phishing-p

  13. A phishing-as-a-service platform targeting the trucking and logistics sectors and widely used platforms therein has been disrupted. The Russian and Armenian #PhaaS operators involved displayed deep industry knowledge, which they parlayed into focused fraud campaigns. databreachtoday.com/phishing-p

  14. KrakenBite continues expanding its phishing-as-a-service ecosystem, now offering 115+ bank-themed phishing pages across multiple regions, with new additions targeting Moroccan institutions.
    The model includes dashboards, automated purchasing, and support channels - resembling SaaS workflows.

    How should defenders adjust their monitoring and response strategies in light of increasingly polished PhaaS kits?

    Source: redhotcyber.com/en/post/kraken

    Follow us for ongoing threat intelligence updates.

    #Infosec #Cybersecurity #ThreatIntel #Phishing #PhaaS #DigitalSecurity #FraudPrevention #CybercrimeTrends #TechNadu

  15. Zwakke 2FA/MFA werkt AVERECHTS

    In security.nl/posting/912441/65- schreef ik eerder deze week:

    2FA (MFA) is ruk.

    Laat de overheid een wachtwoordmanager adviseren die wél op domeinnamen checkt.

    (Dat laatste kan standaard onder Android, iOS en iPadOS - middels "AutoFill").

    Op veler "verzoek" onderbouwde ik die stelling (niet voor de eerste keer) in security.nl/posting/912441/65-.

    En in security.nl/posting/912441/65- legde ik uit waarom online inloggen *lastig* veilig te krijgen is - wat je ook verzint (het blijven shared secrets).

    Vandaag heb ik Microsoft Authenticator ook maar weer eens getest (onder Android). Mijn bevindingen leest u in (de tweede helft van) security.nl/posting/912441/65- - hieronder een stukje daaruit.

    #ZwakkeMFA #SMS #AuthenticatorApps #Zwakke2FA #Weak2FA #WeakMFA #MicrosoftAuthenticator #2FAsucks #MFAsucks #Phishing #NepWebsites #PhaaS #Evilginx2 #SIMswap #SS7 #AcountTakeOver #CookieTheft #AccountLockout

  16. 🔍 Phishing-as-a-Service (#PhaaS) is driving a wave of large-scale, sophisticated attacks against organisations.

    In our new blogpost, we provide an overview of the key techniques, tactics and social engineering schemes that cybercriminals use in AitM phishing attacks.

  17. 🔍 Phishing-as-a-Service (#PhaaS) is driving a wave of large-scale, sophisticated attacks against organisations.

    In our new blogpost, we provide an overview of the key techniques, tactics and social engineering schemes that cybercriminals use in AitM phishing attacks.

  18. This week, we encountered a new phishing campaign utilizing the Tycoon 2FA Phishing-as-a-Service (PhaaS) to bypass multifactor authentication (MFA).

    The RDGA domains have Russian TLDs but are hosted on CloudFlare infrastructure. We have been seeing them use shared infrastructure for a few months now, definitely trying to make detection more challenging. They continue to obfuscate every piece of code but have updated their verification page. Previously, we always saw their custom Cloudflare Turnstile page, but now they also use a new captcha challenge, as shown below.(You can also check it here urlscan.io/result/0195ed8b-7a4 )

    Their old Cloudflare Turnstile page seems to still be their favorite, even though they now change their message more frequently: "Checking response before request" or "Tracking security across platform" are some of the new messages they use.

    Here is a sample of the hundreds of domains we are detecting:
    womivor[.]ru
    nthecatepi[.]ru
    toimlqdo[.]ru
    dantherevin[.]ru
    xptdieemy[.]ru

    #dns #domains #phishing #AitM #PhaaS #tycoon #scam #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #2MFABypass

  19. This week, we encountered a new phishing campaign utilizing the Tycoon 2FA Phishing-as-a-Service (PhaaS) to bypass multifactor authentication (MFA).

    The RDGA domains have Russian TLDs but are hosted on CloudFlare infrastructure. We have been seeing them use shared infrastructure for a few months now, definitely trying to make detection more challenging. They continue to obfuscate every piece of code but have updated their verification page. Previously, we always saw their custom Cloudflare Turnstile page, but now they also use a new captcha challenge, as shown below.(You can also check it here urlscan.io/result/0195ed8b-7a4 )

    Their old Cloudflare Turnstile page seems to still be their favorite, even though they now change their message more frequently: "Checking response before request" or "Tracking security across platform" are some of the new messages they use.

    Here is a sample of the hundreds of domains we are detecting:
    womivor[.]ru
    nthecatepi[.]ru
    toimlqdo[.]ru
    dantherevin[.]ru
    xptdieemy[.]ru

    #dns #domains #phishing #AitM #PhaaS #tycoon #scam #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #2MFABypass

  20. We published a blog yesterday about a PhaaS and phishing kit that employs DoH and DNS MX records to dynamically serve personalized phishing content. It also uses adtech infrastructure to bypass email security and sends stolen credentials to various data collection spaces, such as Telegram, Discord, and email. blogs.infoblox.com/threat-inte

    #dns #doh #mx #adtech #obfuscation #phaas #phishing #phishingkit #threatintel #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #wordpress #spam #telegram #discord #morphingmeerkat

  21. We published a blog yesterday about a PhaaS and phishing kit that employs DoH and DNS MX records to dynamically serve personalized phishing content. It also uses adtech infrastructure to bypass email security and sends stolen credentials to various data collection spaces, such as Telegram, Discord, and email. blogs.infoblox.com/threat-inte

    #dns #doh #mx #adtech #obfuscation #phaas #phishing #phishingkit #threatintel #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #wordpress #spam #telegram #discord #morphingmeerkat

  22. Phishing-as-a-service is an area that is increasing rapidly according to research by security vendor Barracuda Networks, which says it has detected a “massive spike” in PhaaS attacks in the first two months of this year.

    computing.co.uk/news/2025/secu

    #phishing #phaas #tycoon2fa #evilproxy #infosec #cybersecurity #barracuda #technews

  23. Phishing-as-a-service is an area that is increasing rapidly according to research by security vendor Barracuda Networks, which says it has detected a “massive spike” in PhaaS attacks in the first two months of this year.

    computing.co.uk/news/2025/secu

    #phishing #phaas #tycoon2fa #evilproxy #infosec #cybersecurity #barracuda #technews

  24. The new Darcula phishing-as-a-service (PhaaS) platform lets cybercriminals clone any brand’s website and create phishing pages in minutes—no coding skills required. In the past year, 95,000 phishing domains and 31,000 IP addresses have been linked to #Darcula.

    Using this suite, attackers can submit a URL to generate a clone, then select the HTML elements to replace and inject phishing content (e.g., payment forms and login fields) to create a malicious replica of the legitimate landing page. They can then use the admin panel to manage their phishing campaigns and data collection.

    It's getting harder to spot these attacks, so make sure you are training your team to carefully inspect URLs and email addresses, and enter known URLs rather than clicking links. Please contact us if you need help setting up a training program for your team.

    Read about Darcula: thehackernews.com/2025/02/cybe

    #Cybersecurity #Phishing #PhaaS #Infosec #IT #DFIR #CISO #ITsecurity #training #cyberaware #SMB