logo

How Phishing Kits Targeting U.S. Giants Are Built, Sold, and Deployed

ID: 1311dc8e-6462-5aa4-84e7-07ffdf48fce1

STIX ID: report--1311dc8e-6462-5aa4-84e7-07ffdf48fce1

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-04-10

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Modern Phishing-as-a-Service (PhaaS) and AiTM phishing kits now enable attackers to capture authenticated session cookies (effectively bypassing MFA) using reverse-proxy and application-driven architectures; these kits are commercially available via Telegram and underground marketplaces at low cost, abuse trusted cloud infrastructure and QR/email delivery for distribution, and are used by both criminal groups and nation-state actors — creating a high-scale, persistent threat to enterprises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.