Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks

Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks

Posted on July 28, 2026 By CWS

During the week of July 20-26, 2026, phishing kits targeting Microsoft 365 identities saw significant activity, with 7,295 uploads logged globally. The surge was primarily attributed to the abuse of OAuth device-code flows and the use of adversary-in-the-middle (AiTM) kits. Notably, the cybercriminal group Storm-1747, associated with the Tycoon2FA kit, reported 50 uploads, a slight decrease from the previous week due to ongoing law enforcement actions.

Surge in OAuth and AiTM Techniques

The latest data highlights a marked increase in OAuth flow phishing, with an additional 194 incidents, underscoring a shift away from traditional credential-harvesting methods. This trend has been consistently noted by Microsoft, Push Security, and LevelBlue throughout the year. The primary focus remains on exploiting Microsoft 365 accounts by intercepting authentication processes.

The top 10 phishing kits, ranked by activity, include Sneaky2FA, EvilTokens, and Evilginx2/EvilProxy, among others. These kits employ various techniques such as reverse-proxy interception and cookie theft to bypass security measures like multi-factor authentication (MFA).

Detailed Analysis of Leading Kits

Sneaky2FA, despite a decline of 303 uploads, remains the most prevalent kit. It leverages Telegram-based platforms and AiTM proxies to validate credentials against genuine Microsoft interfaces. Meanwhile, EvilTokens, with a rise of 65 uploads, uses OAuth 2.0 device authorization to hijack verified sessions without needing passwords.

Evilginx2 and its commercial counterpart, EvilProxy, continue to intercept traffic between users and identity providers to capture session cookies. Kali365, another prominent kit, facilitates subscription-based device-code token theft, posing significant risks to enterprise users.

Broader Implications and Future Outlook

The persistence of these sophisticated phishing kits highlights the ongoing vulnerabilities in device-code authorization and MFA processes. Industries ranging from finance to technology are particularly targeted, with attackers exploiting unrestricted device-code flows and session cookie replay tactics.

To mitigate these risks, organizations are advised to enforce stricter OAuth flow controls, deploy phishing-resistant MFA solutions, and monitor for unusual device-code usage. As threat actors continue to evolve their methods, it is crucial for cybersecurity teams to stay informed and proactive in protecting their systems.

Looking ahead, the focus should be on enhancing authentication security and tightening access controls to deter these evolving phishing threats. By integrating comprehensive threat intelligence and continuous monitoring, businesses can better safeguard their digital assets against such sophisticated cyberattacks.

Cyber Security News Tags:AiTM, Cyberattacks, Cybersecurity, Evilginx2, EvilTokens, Kali365, MFA bypass, Microsoft 365, OAuth, Phishing, reverse proxy, session cookies, Sneaky2FA, Storm-1747, token theft

Post navigation

Previous Post: Critical Security Update for JetBrains TeamCity Users
Next Post: Chrome Extension Secretly Collects AI Interactions

Related Posts

VoidStealer Variant Evades Chrome Security Without Injection VoidStealer Variant Evades Chrome Security Without Injection Cyber Security News
Microsoft Office.com Suffers Major Outage, Investigation Underway Microsoft Office.com Suffers Major Outage, Investigation Underway Cyber Security News
Everest Ransomware’s Dubious Data Theft Claim Examined Everest Ransomware’s Dubious Data Theft Claim Examined Cyber Security News
ChatGPT Vulnerability Exposes System File Access Risks ChatGPT Vulnerability Exposes System File Access Risks Cyber Security News
Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome Cyber Security News
Top VPNs for Chrome in 2026: Secure Your Browsing Top VPNs for Chrome in 2026: Secure Your Browsing Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark