VYPR
researchPublished Jul 28, 2026· Updated Aug 7, 2026· 5 sources

Phishing-as-a-Service Surges with OAuth Abuse and AiTM Kits Targeting Microsoft 365

Phishing-as-a-service activity saw a significant spike to 7,295 uploads in the week of July 20-26, 2026, primarily driven by the abuse of OAuth device-code flows and adversary-in-the-middle (AiTM) kits targeting Microsoft 365 credentials.

Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026. This dramatic increase was overwhelmingly driven by the abuse of OAuth device-code flows and adversary-in-the-middle (AiTM) kits specifically targeting Microsoft 365 identities. Cybercriminal group Storm-1747, known for operating the Tycoon2FA kit, logged 50 attributed uploads, a slight decrease from the previous week, likely due to ongoing law-enforcement pressure on its infrastructure.

The rise in OAuth flow phishing, which saw a weekly increase of 194 uploads, confirms a significant trend: device-code authentication abuse has now surpassed classic credential-harvesting pages as the primary AiTM technique. This shift has been repeatedly flagged by security researchers from Microsoft, Push Security, and LevelBlue throughout the second and third quarters of 2026.

Among the top-performing phishing kits, Sneaky2FA led with 886 uploads, despite a weekly decline of 303. This kit, first detected in October 2024, is a full-featured Telegram-sold PhaaS platform that specializes in intercepting Microsoft 365 accounts via AiTM reverse-proxy. It validates stolen credentials in real-time against legitimate Microsoft APIs and employs sophisticated techniques like blurred screenshots of real Microsoft interfaces and browser-in-the-browser fake login windows to evade sandbox detection.

Following closely is EvilTokens, a rapidly growing kit with 684 uploads, marking a 65-upload increase. EvilTokens uniquely abuses the OAuth 2.0 device authorization grant flow, enabling attackers to hijack legitimate, MFA-verified Microsoft 365 logins without ever needing the user's password. Delivered via Telegram bots, it bundles token harvesting, email harvesting, reconnaissance, and AI-driven lure generation. Its reconnaissance phase can run 10-15 days ahead of the actual phishing attempt, making early detection crucial.

Evilginx2/EvilProxy, a well-known reverse-proxy framework and its commercialized PhaaS derivative, recorded 660 uploads, a decrease of 199. These tools intercept live traffic between victims and identity providers like Microsoft 365, Okta, and Google Workspace to harvest session cookies post-MFA. Kali365, observed since April 2026 and previously the subject of an FBI advisory, also remains a significant threat with 503 uploads, an increase of 17. This kit steals Microsoft 365 access tokens via device-code phishing, bypassing password and MFA prompts by having victims approve what appears to be a legitimate authorization on a real Microsoft URL.

The data highlights a broader ecosystem of phishing-as-a-service operations, with nine named kits individually tracked, alongside broader technique categories like "OAuth Flow Phishing" and "Suspected Quishing" (QR phishing). These kits are being deployed across various industries, including finance, professional services, technology, HR, logistics, and sales departments within Microsoft 365 enterprise tenants. The vulnerabilities exploited range from MFA bypass via session token relay to the unrestricted abuse of the OAuth 2.0 device authorization grant flow.

This surge in sophisticated phishing kits and techniques underscores the evolving threat landscape, particularly the focus on compromising cloud-based productivity suites like Microsoft 365. The increasing reliance on OAuth flows and AiTM strategies by cybercriminals indicates a growing need for organizations to bolster their defenses against these advanced credential theft and session hijacking methods.

The Greatness PhaaS toolkit has now integrated device code phishing, a technique that leverages the OAuth 2.0 Device Authorization Grant to bypass MFA and conduct adversary-in-the-middle (AiTM) attacks. This new capability allows attackers to steal user credentials and session tokens more silently than previous methods, marking a significant escalation in the sophistication of readily available phishing tools. The platform's subscription costs have also increased, now starting at $289 per month, up from $120 reported earlier this year.

The Greatness phishing-as-a-service (PhaaS) platform has adopted sophisticated adversary-in-the-middle (AiTM) and device-code phishing techniques to target Microsoft 365 accounts. This evolution allows attackers to bypass multi-factor authentication by intercepting legitimate authentication sessions, a tactic also highlighted in recent surges of similar phishing-as-a-service activity. The service specifically spoofs RingCentral to trick victims into initiating the phishing flow, enabling the theft of sensitive credentials and session tokens.

The threat actor UNC6671 has been identified by Google Cloud as continuing data theft operations, previously associated with the BlackFile brand, under new monikers including Redact, Pink, Helix, and Falcon. This group has shifted its targeting towards financial services, private equity, and professional services firms, leveraging vishing tactics to hijack Microsoft 365 and Okta sessions by capturing credentials and live authentication tokens, thereby automating data exfiltration and employing techniques to evade detection.

This campaign specifically targets Microsoft 365 accounts using adversary-in-the-middle (AitM) techniques, aiming to identify and compromise personnel involved in financial workflows. Attackers are employing residential proxies to disguise malicious sign-ins as legitimate consumer traffic and maintain compromised sessions for approximately eight-hour intervals. The campaign shares tactical overlaps with previously tracked Payroll Pirate attacks, also known as Storm-2755, which focus on hijacking accounts to reroute salary payments.

Synthesized by Vypr AI