logo

Phishing kits adapt to the script of callers

ID: e1bad400-9361-54ae-87e0-8d98d1a45df1

STIX ID: report--e1bad400-9361-54ae-87e0-8d98d1a45df1

Feed Name: Threat Intelligence | Blog | Okta

Threat Score
75/100

Date Published: 2026-01-21

Date Updated: 2026-07-16

...
...

Okta Threat Intelligence has identified and analyzed custom phishing kits used in vishing campaigns that let callers control the victim's browser authentication flow to harvest credentials and prompt users to approve MFA or take other actions. These kits, offered as-a-service and in active use against Google, Microsoft, Okta, and cryptocurrency providers, synchronize page presentation with caller scripts to defeat MFA mechanisms that are not phishing-resistant.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.