A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Forg365 is a phishing-as-a-service (PhaaS) operation that uses device code phishing, AitM tactics, and AI-assisted lures to compromise Microsoft 365 accounts. It…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
DEBULL is a reusable tooling layer that packages Storm-2372-style identity tradecraft into a PhaaS platform. It provides campaign-facing and operator-facing infrastructure, using…
ARToken is a fully-featured PhaaS operator panel identified by Cisco Talos, sharing infrastructure with EvilTokens. It exposes over 80 API endpoints for…
An INTERPOL-led operation codenamed Operation Ramz has successfully disrupted Sniper Dz, a decade-old phishing-as-a-service (PhaaS) platform, resulting in 201 arrests across 13…
Sniper Dz was a sophisticated phishing-as-a-service (PhaaS) platform active since at least 2015. It offered ready-made phishing kits, hosting infrastructure, and operational…