Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Greatness is a commercial phishing-as-a-service (PhaaS) toolkit that has evolved to include device code phishing, AiTM token theft, and OAuth consent abuse.…
Tycoon2FA is a well-known AiTM phishing kit that added device code phishing support in May 2026. It was previously tracked as the…
German and US law enforcement, in coordination with Indonesian authorities, have dismantled the infrastructure behind Kratos, a sophisticated phishing kit designed to…
Kratos is a sophisticated phishing kit dismantled by law enforcement in July 2026. It was designed to steal Microsoft 365 session cookies…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Forg365 is a phishing-as-a-service (PhaaS) operation that uses device code phishing, AitM tactics, and AI-assisted lures to compromise Microsoft 365 accounts. It…
Sneaky 2FA is a phishing ecosystem used in conjunction with Forg365 and other kits to bypass two-factor authentication via AitM techniques.
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing…
Evilginx is an open-source adversary-in-the-middle (AiTM) phishing framework used to bypass multi-factor authentication by proxying live login sessions. It has been forked…