#phaas
-A network of 10,000 AI servers masks Chinese malicious activity
-Ukrainian hackers leak Russia's naval secrets
-ShinyHunters hack the FBI
-Tech firms disrupt EvilTokens PhaaS
-BigCommerce notifies merchants of security breach

P: risky.biz/RBNEWS614/
N: news.risky.biz/risky-bullet...
September 23, 2026 at 7:54 AM
Since emerging in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, enabling sophisticated device code phishing campaigns aimed at compromising organizational accounts at scale. msft.it/63321a54KS
Unmasking EvilTokens: Getting to the root of device code phishing | Microsoft Security Blog
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations.
msft.it
September 22, 2026 at 4:17 PM
A new phishing-as-a-service (PhaaS) platform named 'Rockstar 2FA' has emerged, facilitating large-scale adversary-in-the-middle (AiTM) attacks to steal Microsoft 365 credentials.

www.bleepingcomputer.com/news/securit...
New Rockstar 2FA phishing service targets Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) platform named 'Rockstar 2FA' has emerged, facilitating large-scale adversary-in-the-middle (AiTM) attacks to steal Microsoft 365 credentials.
www.bleepingcomputer.com
December 1, 2024 at 2:00 AM
This is a very interesting report from Group-IB.

The company believes it found one of the PhaaS platforms—Phoenix System—working with SMS blaster operations

www.group-ib.com/blog/phoenix...
Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) ...
www.group-ib.com
April 30, 2026 at 11:08 AM
Microsoft and Cloudflare have disrupted a massive Phishing-as-a-Service (PhaaS) operation, known as RaccoonO365, that helped cybercriminals steal thousands of Microsoft 365 credentials.
Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service
Microsoft and Cloudflare have disrupted a massive Phishing-as-a-Service (PhaaS) operation, known as RaccoonO365, that helped cybercriminals steal thousands of Microsoft 365 credentials.
www.bleepingcomputer.com
September 17, 2025 at 1:20 PM
TOTP is not enough anymore.

PassKeys are a minimum requirement for safe logins now.
New VENOM phishing attacks steal senior executives' Microsoft logins
Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called "VENOM" are targeting credentials of C-suite executives across multiple industries.
www.bleepingcomputer.com
April 14, 2026 at 1:04 PM
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.
www.bleepingcomputer.com
August 25, 2026 at 8:25 PM
September 23, 2026 at 5:40 AM
Major exposes on the Darcula PhaaS (actually named Magic Cat) in Norwegian, German, and French media today:

www.br.de/nachrichten/...

www.lemonde.fr/pixels/artic...

www.nrk.no/dokumentar/x...

Also a Mnemonic report here: www.mnemonic.io/resources/bl...
Exposing Darcula: a rare look behind the scenes of a global Phishing-as-a-Service operation
www.mnemonic.io
May 4, 2025 at 11:00 AM
-New malware: GhostFrame PhaaS, Spiderman PhaaS, ChimeraWire, DeadLock ransomware, Broadside botnet, GhostPenguin Linux backdoor
-New GrayBravo group
-ZeroBoot exploit
-ShellShock sees exploitation spike
-3 password managers can access your passwords
-Checkmarx buys Tromzo
December 10, 2025 at 9:23 AM
See No EvilTokens: Disrupting the EvilTokens PhaaS Platform https://packetstorm.news/news/view/43754 #news
September 22, 2026 at 7:31 PM
The Tycoon2FA phishing-as-a-service (PhaaS) platform that Europol and partners disrupted on March 4 has already returned to previously observed activity levels.
Tycoon2FA phishing platform returns after recent police disruption
The Tycoon2FA phishing-as-a-service (PhaaS) platform that Europol and partners disrupted on March 4 has already returned to previously observed activity levels.
www.bleepingcomputer.com
March 23, 2026 at 9:53 PM
-Linux kernel discloses 442 CVEs as AI bugpocalypse settles in
-OpenAI was behind the Hugging Face breach
-France passes kids social media ban
-Germany takes down Kratos PhaaS
-Hackers breached South Korea's MFA for months

N: news.risky.biz/risky-bullet...
Pod: risky.biz/RBNEWS590/
July 22, 2026 at 8:10 AM
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
Police dismantle Kratos phishing platform, arrest developer
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
www.bleepingcomputer.com
July 21, 2026 at 11:07 PM
Cloudforce One has successfully disrupted the criminal enterprise known as Tycoon 2FA, one of the most popular Phishing-as-a-Service (PhaaS) kit providers, in coordination with industry partners.

Read here: https://cfl.re/4uFPZKP
March 24, 2026 at 2:39 PM
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
www.bleepingcomputer.com
September 22, 2026 at 3:00 PM
A new phishing-as-a-service (PhaaS) platform named ' #Rockstar2FA' has emerged, facilitating large-scale adversary-in-the-middle (AiTM) attacks to steal Microsoft 365 credentials.
#Cybersecurity #infosec
www.bleepingcomputer.com/news/securit...
New Rockstar 2FA phishing service targets Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) platform named 'Rockstar 2FA' has emerged, facilitating large-scale adversary-in-the-middle (AiTM) attacks to steal Microsoft 365 credentials.
www.bleepingcomputer.com
November 30, 2024 at 4:23 AM
-Arch Linux supply chain attack hits 1,900+ AUR packages
-FISA S702 expires for the first time since 2008
-US puts exports controls on Anthropic
-FBI takes down Chinese PhaaS
-major supply chain attack hits WP ecosystem

Podcast: risky.biz/podcasts/
Newsletter: news.risky.biz/risky-bullet...
June 15, 2026 at 9:05 AM
Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called "VENOM" are targeting credentials of C-suite executives across multiple industries.
New VENOM phishing attacks steal senior executives' Microsoft logins
Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called "VENOM" are targeting credentials of C-suite executives across multiple industries.
www.bleepingcomputer.com
April 9, 2026 at 9:37 PM
A newly discovered phishing-as-a-service (PhaaS) operation that researchers call Morphing Meerkat, has been using the DNS over HTTPS (DoH) protocol to evade detection.
Phishing-as-a-service operation uses DNS-over-HTTPS for evasion
A newly discovered phishing-as-a-service (PhaaS) operation that researchers call Morphing Meerkat, has been using the DNS over HTTPS (DoH) protocol to evade detection.
www.bleepingcomputer.com
March 28, 2025 at 4:33 PM
An international law enforcement operation coordinated by Europol has disrupted Tycoon2FA, a major phishing-as-a-service (PhaaS) platform linked to tens of millions of phishing messages each month.
Europol-coordinated action disrupts Tycoon2FA phishing platform
An international law enforcement operation coordinated by Europol has disrupted Tycoon2FA, a major phishing-as-a-service (PhaaS) platform linked to tens of millions of phishing messages each month.
www.bleepingcomputer.com
March 4, 2026 at 5:01 PM
The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA).
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA).
www.bleepingcomputer.com
May 25, 2026 at 12:48 PM