Tech News
← Home  ·  All topics

Phishing-As-A-Service

3 GoKawiil briefs on this topic

Microsoft-led coalition dismantles EvilTokens AI phishing-as-a-service network

Microsoft and partners including Cloudflare, Coinbase, OpenAI, SpyCloud, TRM Labs and Health-ISAC disrupted EvilTokens, a phishing-as-a-service platform that used AI to scan compromised inboxes and craft tailored lures. The operation had compromised over 12,000 inboxes across more than 10,000 organizations worldwide, spanning sectors like healthcare, finance and higher education. The takedown seized 50 sites and disabled 150 domains, and UK police arrested two men, aged 32 and 38, after Microsoft shared intelligence with the Metropolitan Police's cybercrime unit.

BigBear 2.0 phishing kit steals 5,000+ Microsoft 365 logins across 258 firms

CloudSEK researchers infiltrated the admin panel of a phishing-as-a-service tool called BigBear 2.0 and found it had harvested over 5,000 Microsoft 365 credentials from 258 organizations. The kit uses an Evilginx2-based adversary-in-the-middle proxy to intercept usernames, passwords, and session cookies even after victims complete multi-factor authentication, letting attackers replay stolen sessions to hijack accounts.

AnonyMousKIT phishing service uses AI voice bots to unlock stolen iPhones

Threat intelligence firm SOCRadar has exposed AnonyMousKIT, a phishing-as-a-service platform active since early 2024 that automates theft of Apple Activation Lock codes needed to unlock stolen iPhones. The operation spans 506 domains and 168 reseller storefronts, and uses AI-driven voice calls impersonating Apple to trick victims into handing over unlock credentials, iCloud data, and Keychain passwords.