Top 10 Phishing Kits Used by Cybercriminals
ID: 9fa60e7c-d163-5b16-9861-ac27edf0295f
STIX ID: report--9fa60e7c-d163-5b16-9861-ac27edf0295f
Feed Name: SOCRadar Blog
This report catalogues the top 10 phishing kits and PhaaS platforms (e.g., Tycoon2FA, EvilProxy, Sneaky 2FA, EvilTokens, Evilginx) active during 2023–2026, describing their attack flows, technical capabilities (AiTM/reverse-proxy, device-code abuse, Browser-in-the-Browser, WebSocket exfiltration), observed scale (including campaigns affecting hundreds to hundreds of thousands of organizations and thousands of domains), recent disruption efforts, and recommended defensive mitigations such as adopting phishing-resistant authentication, monitoring session/token reuse, and restricting device-code flows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
