Phishing-as-a-Service 2.0: The Kits That Bypass MFA Without a Fake Login Page
ID: 4e094d1c-e0fd-532a-9089-113e4bc64ff3
STIX ID: report--4e094d1c-e0fd-532a-9089-113e4bc64ff3
Feed Name: Brandefense Blog
Phishing-as-a-Service 2.0 platforms (notably EvilTokens and Kali365) commercialize OAuth device-code abuse and AiTM reverse-proxy techniques to bypass MFA, capture session cookies and OAuth tokens, and enable large-scale BEC operations with automation and AI; these kits are inexpensive subscriptions, have compromised hundreds of organizations globally, and evade many traditional defenses while offering post-compromise tooling (inbox scraping, ghost-mode notification suppression, token replay).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
