Skip to content
Data Breach

Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)

Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026, driven overwhelmingly by OAuth device-code flow abuse and adversary-in-the-middle (AiTM) kits targeting Mi...

· Jul 28, 2026 · 10 min read · 👁 1 views
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
Top 10 Phishing Kits Used by Hackers
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)

Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026, driven overwhelmingly by OAuth device-code flow abuse and adversary-in-the-middle (AiTM) kits targeting Microsoft 365 identities.

Cybercriminal group Storm-1747, the operator behind Tycoon2FA, logged 50 attributed uploads, down 6 from the prior week following ongoing law-enforcement pressure on its infrastructure.

Weekly Activity Snapshot

CategoryTotal UploadsWeekly Change
OAuth Flow Phishing2,446+194
Suspected Quishing (QR phishing)974-17
PDF-based lures536-111
Malicious URLs229-67
Storm-1747 (cybercriminal group)50-6

The rise in OAuth flow phishing (+194) confirms that device-code authentication abuse has overtaken classic credential-harvesting pages as the primary AiTM technique this week, a trend flagged repeatedly by Microsoft, Push Security, and LevelBlue through Q2-Q3 2026.

Top 10 Phishing Kits Ranked by Weekly Activity

RankKit NameTotal UploadsWeekly ChangePrimary Technique
1Sneaky2FA886-303AiTM reverse proxy, Telegram PhaaS
2EvilTokens684+65OAuth device-code phishing
3Evilginx2/EvilProxy660-199Reverse-proxy AiTM, cookie theft
4Kali365503+17Device-code token theft
5MassBass90-19Emerging PhaaS credential harvester
6Greatness88+30M365 AiTM proxy, MFA/TOTP bypass
7Kratos76-4AiTM session-cookie theft (post-takedown remnants)
8Tycoon2FA46-11AiTM reverse proxy, Storm-1747
9Cephas27-79Obfuscated anti-bot AiTM kit

Nine named kits are tracked individually in the source data; “OAuth Flow Phishing” and “Suspected Quishing” are broader technique categories that overlap with several of the kits above, particularly EvilTokens and Kali365.

Top 10 Phishing Kits
Top 10 Phishing Kits

Detailed Kit Profiles

1. Sneaky2FA 886 uploads (-303)

Sneaky2FA is a full-featured, Telegram-sold PhaaS platform first detected in October 2024 that specifically compromises Microsoft 365 accounts via AiTM reverse-proxy interception.

It validates stolen credentials in real time against legitimate Microsoft APIs, uses blurred screenshots of real Microsoft interfaces as decoy backgrounds, and employs browser-in-the-browser fake login windows to defeat sandbox detection.

Despite the largest weekly decline of any kit (-303), it remains the single most-used phishing kit this week.

  • Infection Vector: Phishing emails with fake payment receipts containing QR codes linking to spoofed Microsoft 365 login pages
  • Tools Used: Telegram-based PhaaS panel, AiTM reverse proxy, browser-in-the-browser overlay
  • Targeted Industries: Enterprise Microsoft 365 tenants across finance, professional services, and technology
  • Vulnerabilities Exploited: OTP/TOTP-based MFA bypass via session token relay; inconsistent User-Agent strings across auth steps reveal “impossible device shifts”

2. EvilTokens 684 uploads (+65)

EvilTokens is a rapidly growing PhaaS kit that abuses the OAuth 2.0 device authorization grant flow, letting attackers hijack a legitimate, MFA-verified Microsoft 365 login without ever touching a password.

Delivered through Telegram bots, it bundles token harvesting, email harvesting, reconnaissance, and AI-driven lure generation, and has already been used in a March 2026 campaign against more than 340 organizations.

Its recon phase runs 10-15 days ahead of the actual phishing attempt, making early detection critical.

  • Infection Vector: Emails disguised as invoices, shared documents, calendar invites, or SharePoint access requests urging victims to “Verify to view”
  • Tools Used: Telegram bot C2, OAuth device-code request automation, AI-driven lure generation
  • Targeted Industries: Finance, HR, logistics, and sales departments within Microsoft 365 enterprise tenants
  • Vulnerabilities Exploited: OAuth 2.0 device authorization grant flow abuse; no Conditional Access restriction on device-code sign-ins

3. Evilginx2 / EvilProxy 660 uploads (-199)

Evilginx2 is an open-source, red-team-turned-criminal reverse-proxy framework, while EvilProxy is its commercialized PhaaS derivative sold from $150-$400/month on dark web forums.

Both intercept live traffic between victims and real identity providers (Microsoft 365, Okta, Google Workspace) to harvest session cookies post-MFA.

  • Infection Vector: Phishing links directing victims to attacker-controlled reverse-proxy domains that mirror real login pages
  • Tools Used: Evilginx2/Modlishka/Muraena-style reverse proxy, cookie injection modules, dark-web subscription panels
  • Targeted Industries: Fortune 500 enterprises, SaaS and cloud-service consumers globally
  • Vulnerabilities Exploited: Session-cookie replay after legitimate MFA completion; lack of FIDO2-bound authentication

4. Kali365 503 uploads (+17)

Kali365, first observed in April 2026 and subject to an FBI advisory, is a subscription PhaaS kit (US$250/month or US$2,000/year) that steals Microsoft 365 access tokens via device-code phishing, entirely bypassing password entry and MFA prompts.

Victims approve what looks like a document-share or Teams-invite code on a genuine Microsoft URL, unknowingly authorizing the attacker’s session.

  • Infection Vector: Fake document-share/Teams-invite messages instructing victims to enter a device code at a real Microsoft URL
  • Tools Used: Telegram promotion channel, device-code flow automation, persistent OAuth token harvesting
  • Targeted Industries: Broad enterprise and SMB Microsoft 365 users; shared conference-room/IoT device abuse also observed
  • Vulnerabilities Exploited: Unrestricted device-code authorization grant flow; authentication-state transfer between devices

5. MassBass 90 uploads (-19)

  • Infection Vector: Malicious email links and attachments consistent with commodity PhaaS distribution patterns
  • Tools Used: Templated login-page cloning, credential-exfiltration backend typical of PhaaS kits
  • Targeted Industries: Cross-sector, consistent with mass-distribution PhaaS campaigns
  • Vulnerabilities Exploited: Credential and session-token harvesting via cloned authentication pages

6. Greatness 88 uploads (+30)

Active since November 2022, Greatness is a mature PhaaS tool with MFA bypass, IP filtering, and Telegram bot integration, focused exclusively on Microsoft 365 phishing pages.

It pre-fills the victim’s email address and injects the target company’s real logo and background, making it especially convincing for business users.

Campaigns concentrate on manufacturing, healthcare, and technology firms in the US, UK, Australia, South Africa, and Canada.

  • Infection Vector: Phishing emails with attachment/link builder generating decoy and login pages
  • Tools Used: API-driven phishing kit, Telegram bot notifications, TOTP-capturing proxy
  • Targeted Industries: Manufacturing, healthcare, and technology sectors across five countries
  • Vulnerabilities Exploited: TOTP/MFA bypass via man-in-the-middle proxying of Microsoft 365 authentication

7. Kratos 76 uploads (-4)

Kratos was dismantled by German (BKA/ZIT) and US law enforcement in July 2026, with over 200 servers seized and its alleged Indonesian developer arrested; investigators estimate 1,800 paying customers ran roughly 15,000 monthly campaigns.

Despite the takedown, residual activity (76 uploads, -4) persists because the kit code remains in criminal hands. Kratos harvested both credentials and session cookies, defeating MFA entirely.

  • Infection Vector: Phishing pages mimicking Microsoft 365 login, often via BEC-style lures
  • Tools Used: AiTM proxy; forensic signature includes login pages loading barr.svg and lg.svg assets, posting stolen data to next.php or save.php endpoints
  • Targeted Industries: Global enterprise organizations, heavy BEC use for financial fraud
  • Vulnerabilities Exploited: Session-cookie theft enabling MFA bypass; lack of monitoring for AiTM proxy signatures

8. Tycoon2FA 46 uploads (-11)

Tycoon2FA, operated by threat actor Storm-1747, has been the dominant global AiTM PhaaS platform since August 2023, at its peak responsible for an estimated 44.5% of all credential-theft attacks and 89% of the AiTM PhaaS market in 2025.

A 2026 law-enforcement disruption reduced its footprint, and this week’s -11 change reflects continued decay, though Barracuda notes the ecosystem has redistributed rather than disappeared.

  • Infection Vector: Fake CAPTCHA-gated phishing pages and Microsoft/Gmail login clones distributed via phishing email
  • Tools Used: Reverse-proxy AiTM server, Cloudflare Turnstile CAPTCHA abuse, JavaScript fingerprinting, geofencing, Telegram real-time alerting
  • Targeted Industries: Defense, manufacturing, insurance, and technology sectors globally
  • Vulnerabilities Exploited: Real-time session-cookie/token capture post-MFA; OAuth app-consent grant abuse

9. Cephas 27 uploads (-79)

Cephas, first seen in August 2024, is an obfuscated AiTM kit notable for embedding random invisible characters and astronomy/bible-themed code comments to evade YARA-rule and pattern-based detection.

It validates stolen credentials and session tokens directly against Microsoft APIs during submission and logged the sharpest weekly drop (-79) among named kits this week.

  • Infection Vector: Business-inquiry-themed phishing emails leading to file-sharing platform downloads
  • Tools Used: Anti-bot/anti-analysis obfuscation, Microsoft API credential validation, steganographic payload delivery in related campaigns
  • Targeted Industries: Cross-sector Microsoft 365 environments
  • Vulnerabilities Exploited: Static/pattern-based scanner evasion; credential/token validation bypasses fraud-detection heuristics

Known Infection Vectors (Cross-Kit Summary)

  • Device-code phishing lures disguised as document-share, calendar-invite, or SharePoint-access notifications
  • QR-code (“quishing”) embedded in fake invoice/payment-receipt PDFs, now 974 weekly uploads
  • Fake CAPTCHA-gated landing pages preceding credential-harvesting redirects
  • Compromised legitimate platforms abused as senders or URL redirectors, plus multi-layered link-rewriter chains
  • Business-inquiry emails driving downloads from legitimate file-sharing services carrying obfuscated JavaScript and malicious scripts

Known Tools Used by Attackers

  • Telegram bots for real-time credential alerts, C2, and PhaaS kit distribution/sales
  • AiTM reverse-proxy frameworks (Evilginx2, Muraena, Modlishka lineage)
  • OAuth 2.0 device-authorization-grant automation scripts
  • Cloudflare Turnstile and other CAPTCHA-abuse modules for anti-bot evasion
  • Browser-in-the-browser (BitB) fake login overlays
  • Code obfuscation via invisible Unicode characters and steganographic image payloads

Targeted Industries

IndustryKits Observed Targeting It
Finance & InsuranceEvilTokens, Tycoon2FA, Kratos
ManufacturingGreatness, Tycoon2FA
HealthcareGreatness
Technology / SaaSSneaky2FA, Evilginx2/EvilProxy, Tycoon2FA
Government / DefenseTycoon2FA
HR, Logistics, Sales (functional targeting)EvilTokens

Common Vulnerabilities and Weaknesses Exploited

  • Unrestricted OAuth device-code authorization flow in Microsoft Entra ID tenants, the single biggest enabler behind EvilTokens, Kali365, and Tycoon2FA’s newer device-code module
  • Session-cookie/token replay after legitimate MFA completion, defeating SMS, push, and TOTP-based second factors
  • Authentication-state transfer between devices left unrestricted in Entra ID, exploited by Kali365
  • Lack of Conditional Access scoping on device-code, geolocation, and device-compliance signals
  • Absent phishing-resistant MFA (FIDO2/WebAuthn/passkeys), leaving OTP/push-based MFA vulnerable to AiTM interception
  • Weak anti-phishing pattern detection, bypassed by Cephas’s invisible-character obfuscation and Sneaky2FA’s browser-in-the-browser rendering

Full List of Indicators of Compromise (IOCs)

Domains and URLs

IndicatorAssociated Kit
authdocspro[.]comEvilTokens
backdoor-hub[.]comEvilTokens
bumpgames[.]netEvilTokens
carbatterygurgaon[.]comEvilTokens
careldutoit-el[.]co[.]zaEvilTokens
dao[.]com[.]auEvilTokens
docusend[.]netEvilTokens
ssolutionmail[.]comEvilTokens
eqfit[.]co[.]zaEvilTokens
eventcalender-schedule[.]comEvilTokens
evobothub[.]orgEvilTokens
m365-verification[.]ruTycoon2FA
authportal-gmail[.]orgTycoon2FA
tycoonkit-login[.]suTycoon2FA
evilproxy[.]proEvilProxy
top-cyber[.]clubEvilProxy
rproxy[.]io / login-live.rproxy[.]ioEvilProxy
msdnmail[.]netEvilProxy
dwbud[.]vilaribit[.]comKratos-family kit
api[.]telegram[.]org (exfil endpoint)Multiple PhaaS kits (Telegram C2)
geoplugin[.]net (victim geolocation)Kratos-family kit

File Paths and Endpoints

IndicatorAssociated Kit
/cllascio.phpTycoon2FA
/PTT/SOftKratos-family kit
next.php, save.php (credential POST endpoints)Kratos
barr.svg, lg.svg (paired login-page assets, 90% detection recall)Kratos

IP Addresses

IndicatorAssociated Kit
147[.]78[.]47[.]250EvilProxy
185[.]158[.]251[.]169EvilProxy
194[.]76[.]226[.]166EvilProxy
185.231.204.77Tycoon2FA
193.124.182.69Tycoon2FA
41.128.0.142 (Egypt-based relay origin)Kratos-family kit

Behavioral/Detection Indicators

  • Impossible device shifts: inconsistent User-Agent strings across authentication steps within a single session (Sneaky2FA)
  • Device-code sign-ins from unfamiliar devices, unusual geographies, or accounts that don’t normally use device-code flow
  • New or modified inbox rules (auto-delete, external forwarding, move-to-RSS-Feeds) following account compromise
  • Mass Microsoft Graph API mailbox reads/bulk searches inconsistent with baseline user behavior
  • Unexpected OAuth application consent grants in tenant audit logs
  • Phishing subject-line template pattern: “Notice of charge – [6-digit number]” / DocuSign-themed lures

MITRE ATT&CK Mapping

  • T1566 (Phishing): Initial access via document/invoice-themed lures across all nine kits
  • T1557 (Adversary-in-the-Middle): Core technique for Sneaky2FA, Evilginx2/EvilProxy, Tycoon2FA, Kratos, Greatness, Cephas
  • T1567 (Exfiltration Over Web Service): Telegram Bot API used for credential/session exfiltration
  • T1550.001 (Use of Application Access Token): OAuth token abuse central to EvilTokens and Kali365 device-code campaigns

Defensive Recommendations for SOC Teams

  • Restrict or disable OAuth device-code flow in Microsoft Entra ID via Conditional Access unless explicitly required by IoT/CLI workflows
  • Deploy phishing-resistant MFA (FIDO2/WebAuthn, passkeys) for all users, prioritizing privileged accounts, since it cryptographically binds authentication to the legitimate origin and defeats classic AiTM relay
  • Monitor sign-in and Graph API logs for anomalous device-code usage, mass mailbox reads, and new inbox-rule creation
  • Audit OAuth app consent grants regularly to catch unauthorized token issuance before lateral movement or BEC occurs
  • Revoke sessions and refresh tokens immediately upon suspected compromise, and treat unsolicited device-code requests as inherently suspicious regardless of the legitimacy of the hosting page
  • Feed the IOCs above into email gateways, web proxies, and SIEM detection rules, and enrich with threat intelligence platforms such as ANY.RUN TI Lookup for real-time correlation against new phishing infrastructure

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you