Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Phishing-as-a-Service Kits Bypass MFA for M365 Breaches

Phishing-as-a-Service Kits Bypass MFA for M365 Breaches

Posted on August 5, 2026 By CWS

Three distinct Phishing-as-a-Service (PhaaS) platforms are targeting US organizations, aiming to compromise Microsoft 365 credentials by circumventing Multi-Factor Authentication (MFA). The platforms—Sneaky 2FA, EvilTokens, and EvilProxy—exploit MFA vulnerabilities, posing significant security threats.

Innovative Attack Techniques

Each PhaaS platform uses unique methods to bypass MFA. Sneaky 2FA employs Adversary-in-the-Middle (AiTM) session hijacking, EvilTokens exploits OAuth device-code authorization, and EvilProxy utilizes real-time reverse-proxy credential relays. Despite different tactics, all aim to deliver authenticated Microsoft 365 sessions to attackers.

The platforms enable attackers to capture session tokens without breaking MFA protocols, undermining traditional security measures like enabling MFA. Users complete legitimate MFA challenges, unaware that session tokens are being intercepted.

Sneaky 2FA: Session Cookie Theft

Identified by Sekoia in late 2024, Sneaky 2FA is an AiTM phishing kit that mimics Microsoft authentication pages to capture session cookies. Its infrastructure includes CAPTCHA challenges to evade automated detection and employs IP filtering to redirect non-target traffic.

Sneaky 2FA’s attack chain involves victims completing MFA on genuine Microsoft servers, with session cookies intercepted by attackers for unauthorized account access. Detection relies on identifying inconsistent User-Agent strings during authentication.

EvilTokens and EvilProxy: Advanced Exploits

EvilTokens, emerging in February 2026, manipulates Microsoft’s OAuth 2.0 Device Authorization flow to acquire tokens. Victims authorize attackers via genuine Microsoft pages, leading to unauthorized API access without raising alerts.

EvilProxy, operational since May 2022, acts as a reverse proxy, capturing credentials and session tokens during legitimate login processes. It evades detection through sophisticated infrastructure mimicking genuine login interfaces.

Defense Strategies and Future Outlook

To combat these threats, organizations must adopt phishing-resistant MFA solutions like FIDO2/WebAuthn to prevent token interception. Restricting OAuth Device Authorization flows and implementing robust detection measures, such as monitoring unusual MFA prompts and URL patterns, are crucial.

As PhaaS platforms evolve, continuous vigilance and proactive defense strategies are essential to safeguard against these sophisticated phishing attacks, ensuring the integrity of organizational cybersecurity frameworks.

Cyber Security News Tags:attack vectors, cloud security, cyber defense, Cybersecurity, email compromise, EvilProxy, EvilTokens, M365 security, MFA bypass, OAuth abuse, phishing-as-a-service, reverse proxy, session hijacking, Sneaky 2FA, threat detection

Post navigation

Previous Post: Phishing Platform Greatness Bypasses MFA for Microsoft 365

Related Posts

Microsoft’s Plan to Phase Out NTLM for Enhanced Security Microsoft’s Plan to Phase Out NTLM for Enhanced Security Cyber Security News
Microsoft Defender XDR New Advanced Hunting Tables for Email and Cloud Protections Microsoft Defender XDR New Advanced Hunting Tables for Email and Cloud Protections Cyber Security News
Chrome Security Update Patches Critical Remote Code Execution Vulnerability Chrome Security Update Patches Critical Remote Code Execution Vulnerability Cyber Security News
Microsoft Defender for Office 365 to Block Email Bombing Attacks Microsoft Defender for Office 365 to Block Email Bombing Attacks Cyber Security News
Google and FBI Disrupt NetNut Proxy Network Exploiting Devices Google and FBI Disrupt NetNut Proxy Network Exploiting Devices Cyber Security News
Hackers Can Exfiltrate Windows Secrets and Credentials Silently by Evading EDR Detection Hackers Can Exfiltrate Windows Secrets and Credentials Silently by Evading EDR Detection Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing-as-a-Service Kits Bypass MFA for M365 Breaches
  • Phishing Platform Greatness Bypasses MFA for Microsoft 365
  • Uppsala Security Joins Cyber Threat Alliance for Blockchain Insight
  • Exposed n8n API Tokens Risk Credential Theft
  • Fraudulent AI Token Sales Exploit Free Cloud Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing-as-a-Service Kits Bypass MFA for M365 Breaches
  • Phishing Platform Greatness Bypasses MFA for Microsoft 365
  • Uppsala Security Joins Cyber Threat Alliance for Blockchain Insight
  • Exposed n8n API Tokens Risk Credential Theft
  • Fraudulent AI Token Sales Exploit Free Cloud Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark