Cybersecurity researchers have disclosed a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies, which is used as a proxy to redirect Microsoft 365…
NovaCookies is a subscription-based phishing-as-a-service (PhaaS) toolkit that uses adversary-in-the-middle (AitM) techniques to steal Microsoft 365 sessions. It is sold for $320…
Suspected Russian cyber espionage groups are abusing legitimate authentication flows, including Google OAuth and WhatsApp device linking, to hijack accounts across Europe…
CornFlake RAT is a Go-based remote access trojan deployed via adversary-in-the-middle (AitM) attacks, often disguised as browser or OS updates. It performs…
Work Panel is a custom console used by UNC6671 for role-based access control, target reconnaissance, automated infrastructure provisioning, and real-time credential relay…
UNC6671, also known as Cordial Spider, has been running an adversary-in-the-middle (AitM) operation since April, targeting financial services and other industries under…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Greatness is a commercial phishing-as-a-service (PhaaS) toolkit that has evolved to include device code phishing, AiTM token theft, and OAuth consent abuse.…