Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
ID: ae8acd0c-632b-5d4d-a102-6bbc85be9c62
STIX ID: report--ae8acd0c-632b-5d4d-a102-6bbc85be9c62
Feed Name: cybersecurityNews.com
Threat Score
**Three PhaaS platforms (Sneaky 2FA, EvilTokens, EvilProxy) are actively compromising Microsoft 365 accounts by relaying real MFA flows or abusing the OAuth Device Authorization Grant to obtain session cookies or tokens; the report details each kit’s attack chain, IOCs, MITRE mappings, detection opportunities, and mitigation advice (phishing-resistant MFA, blocking device-code flows, Sigma/KQL rules for impossible device shifts).**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
