VYPR
researchPublished Jul 28, 2026· 1 source

Phishing-as-a-Service Surges with OAuth Abuse and AiTM Kits Targeting Microsoft 365

Phishing-as-a-service activity saw a significant spike to 7,295 uploads in the week of July 20-26, 2026, primarily driven by the abuse of OAuth device-code flows and adversary-in-the-middle (AiTM) kits targeting Microsoft 365 credentials.

Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026. This dramatic increase was overwhelmingly driven by the abuse of OAuth device-code flows and adversary-in-the-middle (AiTM) kits specifically targeting Microsoft 365 identities. Cybercriminal group Storm-1747, known for operating the Tycoon2FA kit, logged 50 attributed uploads, a slight decrease from the previous week, likely due to ongoing law-enforcement pressure on its infrastructure.

The rise in OAuth flow phishing, which saw a weekly increase of 194 uploads, confirms a significant trend: device-code authentication abuse has now surpassed classic credential-harvesting pages as the primary AiTM technique. This shift has been repeatedly flagged by security researchers from Microsoft, Push Security, and LevelBlue throughout the second and third quarters of 2026.

Among the top-performing phishing kits, Sneaky2FA led with 886 uploads, despite a weekly decline of 303. This kit, first detected in October 2024, is a full-featured Telegram-sold PhaaS platform that specializes in intercepting Microsoft 365 accounts via AiTM reverse-proxy. It validates stolen credentials in real-time against legitimate Microsoft APIs and employs sophisticated techniques like blurred screenshots of real Microsoft interfaces and browser-in-the-browser fake login windows to evade sandbox detection.

Following closely is EvilTokens, a rapidly growing kit with 684 uploads, marking a 65-upload increase. EvilTokens uniquely abuses the OAuth 2.0 device authorization grant flow, enabling attackers to hijack legitimate, MFA-verified Microsoft 365 logins without ever needing the user's password. Delivered via Telegram bots, it bundles token harvesting, email harvesting, reconnaissance, and AI-driven lure generation. Its reconnaissance phase can run 10-15 days ahead of the actual phishing attempt, making early detection crucial.

Evilginx2/EvilProxy, a well-known reverse-proxy framework and its commercialized PhaaS derivative, recorded 660 uploads, a decrease of 199. These tools intercept live traffic between victims and identity providers like Microsoft 365, Okta, and Google Workspace to harvest session cookies post-MFA. Kali365, observed since April 2026 and previously the subject of an FBI advisory, also remains a significant threat with 503 uploads, an increase of 17. This kit steals Microsoft 365 access tokens via device-code phishing, bypassing password and MFA prompts by having victims approve what appears to be a legitimate authorization on a real Microsoft URL.

The data highlights a broader ecosystem of phishing-as-a-service operations, with nine named kits individually tracked, alongside broader technique categories like "OAuth Flow Phishing" and "Suspected Quishing" (QR phishing). These kits are being deployed across various industries, including finance, professional services, technology, HR, logistics, and sales departments within Microsoft 365 enterprise tenants. The vulnerabilities exploited range from MFA bypass via session token relay to the unrestricted abuse of the OAuth 2.0 device authorization grant flow.

This surge in sophisticated phishing kits and techniques underscores the evolving threat landscape, particularly the focus on compromising cloud-based productivity suites like Microsoft 365. The increasing reliance on OAuth flows and AiTM strategies by cybercriminals indicates a growing need for organizations to bolster their defenses against these advanced credential theft and session hijacking methods.

Synthesized by Vypr AI