Tycoon2FA: Adding Device Code Phishing to Its Arsenal
Tycoon2FA is a well-known AiTM phishing kit that added device code phishing support in May 2026. It was previously tracked as the…
Tycoon2FA is a well-known AiTM phishing kit that added device code phishing support in May 2026. It was previously tracked as the…
German and US law enforcement, in coordination with Indonesian authorities, have dismantled the infrastructure behind Kratos, a sophisticated phishing kit designed to…
Kratos is a sophisticated phishing kit dismantled by law enforcement in July 2026. It was designed to steal Microsoft 365 session cookies…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Sneaky 2FA is a phishing kit that focuses on Microsoft accounts. NovaCookies is assessed to be a variant of Sneaky 2FA, but…
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing…
Evilginx is an open-source adversary-in-the-middle (AiTM) phishing framework used to bypass multi-factor authentication by proxying live login sessions. It has been forked…
Microsoft 365 is a productivity and collaboration suite that is a primary target for NovaCookies and other phishing kits. The AitM relay…
ReliaQuest, a cybersecurity company, documented the CaptiveCrunch campaign, which targets captive Wi-Fi portals to steal credentials via AitM attacks.