AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat Landscape — Threadlinqs Intelligence
As of 2026-08-04, AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat Landscape is a high-severity threat intel threat attributed to Storm-1167 (Russia (GREYVIBE nexus)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1879 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Storm-1167 · Russia (GREYVIBE nexus) · FINANCIAL
AI-powered phishing and adversary-in-the-middle (AiTM) Phishing-as-a-Service (PhaaS) platforms have created an escalating threat landscape in 2025-2026. Over 10 major PhaaS platforms — including
The phishing landscape has undergone a fundamental transformation in 2025-2026, driven by two converging trends: the commoditization of adversary-in-the-middle (AiTM) phishing kits as a service, and the integration of generative AI across the entire phishing lifecycle.
## AiTM Phishing-as-a-Service (PhaaS) Ecosystem
At least 12 active PhaaS platforms now compete in a mature underground market, with subscription prices ranging from $100 to $1,000 per month. These platforms provide turnkey phishing infrastructure including email templates, attachment templates (HTML, SVG), anti-bot CAPTCHA gates, administration panels, and Telegram-based credential exfiltration. Sales occur primarily through Telegram channels and private groups, with some operators using Signal, Session, SimpleX, or Tox for operational security.
Sekoia's global analysis (January-April 2025) ranked Tycoon 2FA as the most prominent platform (4.8/5), followed by Storm-1167/FlowerStorm (4.2/5), NakedPages (4.0/5), Sneaky 2FA (3.6/5), EvilProxy (3.2/5), and Evilginx-ywnjb (3.2/5). Tycoon 2FA operates as a synchronous relay server with centralized infrastructure, registering dozens of new domains daily behind Cloudflare, with source code and anti-bot pages updated weekly. Storm-1167, tracked by Microsoft since June 2023, operates a large centralized PhaaS with hundreds of active affiliates. FlowerStorm (first seen June 2024) is assessed as a likely rebrand of the Rockstar 2FA platform after its disruption in 2024 and targets Microsoft 365 credentials.
Infoblox's analysis of a global procurement-themed AiTM campaign identified a single actor rotating between multiple PhaaS platforms — EvilProxy, FlowerStorm, and Kali365 — to maintain operational resilience. The campaign used compromised aged domains (average age >6 years, with one domain dormant for nearly a decade before serving malicious content in May 2026) for fake document download portals, CAPTCHA gates via Cloudflare Turnstile, and reverse-proxy AiTM pages that intercept credentials and MFA session tokens in real time. Lures were sent from previously compromised organizational accounts and themed around procurement (RFIs, bid invitations, shared project documentation) with fake deadlines and confidentiality language to pressure recipients.
JUMPSEC documented a parallel AiTM campaign targeting UK industrial sectors (manufacturing, construction, oil and gas, engineering), first detected February 27, 2025 and still active. This campaign used a commercially available AiTM kit deployed primarily on DigitalOcean infrastructure, with Cloudflare CAPTCHA gates, and exhibited a 12.3% daily average increase in observed results (from 184 on March 11 to 290 on March 27, 2025). The attackers' infrastructure blocks reconnaissance scans from Shodan and ZoomEye but allows Censys queries, providing a fingerprinting vector for defenders.
## Distribution Technique Evolution
Sekoia documented a clear evolution in phishing attachment distribution methods: QR codes in documents dominated in 2023, followed by HTML attachments in 2024, and a surge in SVG attachments from late 2024 through April 2025. SVG files contain either embedded JavaScript or xlink:href attributes to redirect to the AiTM proxy chain. Several PhaaS providers now offer ready-to-use SVG and HTML attachment templates as part of their subscription packages. Traffic Distribution Systems (TDS) — such as BlackTDS (Tycoon 2FA) and Adspect TDS (Mamba 2FA) — filter bot traffic and researchers before victims reach the phishing page.
## GREYVIBE: AI-Enhanced State-Aligned Phishing Operations
GREYVIBE, a Russia-linked threat cluster active since August 2025, represents the most documented case of systematic AI integration across the phishing lifecycle. Active in 2026, the group operates five parallel attack chains (PhantomMail, PhantomClick, PrincessClub, DroneLink, Nebo) targeting Ukrainian military personnel, government agencies, and civilian infrastructure. They use
Target sectors: government administration, military, finance, manufacturing, energy, construction, defense, health, technology, legal
Target regions: North America, Europe, ukraine, united kingdom, Global
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1566.002, T1566.001, T1078, T1059, T1204, T1505, T1557, T1027, T1497, T1056