Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks

Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks

Posted on July 28, 2026 By CWS

During the week of July 20-26, 2026, phishing kits targeting Microsoft 365 identities saw significant activity, with 7,295 uploads logged globally. The surge was primarily attributed to the abuse of OAuth device-code flows and the use of adversary-in-the-middle (AiTM) kits. Notably, the cybercriminal group Storm-1747, associated with the Tycoon2FA kit, reported 50 uploads, a slight decrease from the previous week due to ongoing law enforcement actions.

Surge in OAuth and AiTM Techniques

The latest data highlights a marked increase in OAuth flow phishing, with an additional 194 incidents, underscoring a shift away from traditional credential-harvesting methods. This trend has been consistently noted by Microsoft, Push Security, and LevelBlue throughout the year. The primary focus remains on exploiting Microsoft 365 accounts by intercepting authentication processes.

The top 10 phishing kits, ranked by activity, include Sneaky2FA, EvilTokens, and Evilginx2/EvilProxy, among others. These kits employ various techniques such as reverse-proxy interception and cookie theft to bypass security measures like multi-factor authentication (MFA).

Detailed Analysis of Leading Kits

Sneaky2FA, despite a decline of 303 uploads, remains the most prevalent kit. It leverages Telegram-based platforms and AiTM proxies to validate credentials against genuine Microsoft interfaces. Meanwhile, EvilTokens, with a rise of 65 uploads, uses OAuth 2.0 device authorization to hijack verified sessions without needing passwords.

Evilginx2 and its commercial counterpart, EvilProxy, continue to intercept traffic between users and identity providers to capture session cookies. Kali365, another prominent kit, facilitates subscription-based device-code token theft, posing significant risks to enterprise users.

Broader Implications and Future Outlook

The persistence of these sophisticated phishing kits highlights the ongoing vulnerabilities in device-code authorization and MFA processes. Industries ranging from finance to technology are particularly targeted, with attackers exploiting unrestricted device-code flows and session cookie replay tactics.

To mitigate these risks, organizations are advised to enforce stricter OAuth flow controls, deploy phishing-resistant MFA solutions, and monitor for unusual device-code usage. As threat actors continue to evolve their methods, it is crucial for cybersecurity teams to stay informed and proactive in protecting their systems.

Looking ahead, the focus should be on enhancing authentication security and tightening access controls to deter these evolving phishing threats. By integrating comprehensive threat intelligence and continuous monitoring, businesses can better safeguard their digital assets against such sophisticated cyberattacks.

Cyber Security News Tags:AiTM, Cyberattacks, Cybersecurity, Evilginx2, EvilTokens, Kali365, MFA bypass, Microsoft 365, OAuth, Phishing, reverse proxy, session cookies, Sneaky2FA, Storm-1747, token theft

Post navigation

Previous Post: Critical Security Update for JetBrains TeamCity Users

Related Posts

Critical AWS-LC Vulnerabilities Expose Security Risks Critical AWS-LC Vulnerabilities Expose Security Risks Cyber Security News
New AmCache EvilHunter Tool For Detecting Malicious Activities in Windows Systems New AmCache EvilHunter Tool For Detecting Malicious Activities in Windows Systems Cyber Security News
Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads Cyber Security News
Understanding the Expiration of Threat Intelligence IOCs Understanding the Expiration of Threat Intelligence IOCs Cyber Security News
WordPress TI WooCommerce Wishlist Plugin Vulnerability Exposes 100,000+ Websites To Cyberattack WordPress TI WooCommerce Wishlist Plugin Vulnerability Exposes 100,000+ Websites To Cyberattack Cyber Security News
DarkMoon Launches AI-Driven Penetration Testing Platform DarkMoon Launches AI-Driven Penetration Testing Platform Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis
  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis
  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark