New Phishing Kit As-a-service Attacking Google, Microsoft, and Okta Users
ID: b68e9951-0573-51cc-a612-39e9ebd17882
STIX ID: report--b68e9951-0573-51cc-a612-39e9ebd17882
Feed Name: cybersecurityNews.com
The report describes a new generation of phishing-as-a-service kits that combine browser-based real-time session manipulation with voice social engineering to intercept credentials and bypass MFA for employees at major platforms (Google, Microsoft, Okta, crypto services). Attackers gather target details, spoof company numbers, relay stolen credentials via Telegram, probe authentication flows, and dynamically present fake MFA challenge screens to trick users into approving logins; phishing-resistant methods like FIDO/passkeys are recommended to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
