During the week of July 20-26, 2026, phishing kits targeting Microsoft 365 identities saw significant activity, with 7,295 uploads logged globally. The surge was primarily attributed to the abuse of OAuth device-code flows and the use of adversary-in-the-middle (AiTM) kits. Notably, the cybercriminal group Storm-1747, associated with the Tycoon2FA kit, reported 50 uploads, a slight decrease from the previous week due to ongoing law enforcement actions.
Surge in OAuth and AiTM Techniques
The latest data highlights a marked increase in OAuth flow phishing, with an additional 194 incidents, underscoring a shift away from traditional credential-harvesting methods. This trend has been consistently noted by Microsoft, Push Security, and LevelBlue throughout the year. The primary focus remains on exploiting Microsoft 365 accounts by intercepting authentication processes.
The top 10 phishing kits, ranked by activity, include Sneaky2FA, EvilTokens, and Evilginx2/EvilProxy, among others. These kits employ various techniques such as reverse-proxy interception and cookie theft to bypass security measures like multi-factor authentication (MFA).
Detailed Analysis of Leading Kits
Sneaky2FA, despite a decline of 303 uploads, remains the most prevalent kit. It leverages Telegram-based platforms and AiTM proxies to validate credentials against genuine Microsoft interfaces. Meanwhile, EvilTokens, with a rise of 65 uploads, uses OAuth 2.0 device authorization to hijack verified sessions without needing passwords.
Evilginx2 and its commercial counterpart, EvilProxy, continue to intercept traffic between users and identity providers to capture session cookies. Kali365, another prominent kit, facilitates subscription-based device-code token theft, posing significant risks to enterprise users.
Broader Implications and Future Outlook
The persistence of these sophisticated phishing kits highlights the ongoing vulnerabilities in device-code authorization and MFA processes. Industries ranging from finance to technology are particularly targeted, with attackers exploiting unrestricted device-code flows and session cookie replay tactics.
To mitigate these risks, organizations are advised to enforce stricter OAuth flow controls, deploy phishing-resistant MFA solutions, and monitor for unusual device-code usage. As threat actors continue to evolve their methods, it is crucial for cybersecurity teams to stay informed and proactive in protecting their systems.
Looking ahead, the focus should be on enhancing authentication security and tightening access controls to deter these evolving phishing threats. By integrating comprehensive threat intelligence and continuous monitoring, businesses can better safeguard their digital assets against such sophisticated cyberattacks.
