Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026) — Threadlinqs Intelligence
As of 2026-08-15, Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026) is a high-severity phishing threat attributed to Multiple Phishing-as-a-Service Operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-2024 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Multiple Phishing-as-a-Service Operators · FINANCIAL
SOCRadar's August 12, 2026 roundup profiles ten active phishing-as-a-service (PhaaS) platforms — Tycoon2FA, EvilProxy/Evilginx2, Sneaky 2FA, EvilTokens, BlueKit, CryptoChameleon,
This threat aggregates ten commercially available phishing-kit platforms that SOCRadar identified as currently active and responsible for the bulk of enterprise-identity and consumer phishing traffic as of August 2026. The kits split into two operational families.
The first family — Tycoon2FA, EvilProxy (the commercialized fork of the open-source Evilginx2), and Sneaky 2FA — are reverse-proxy adversary-in-the-middle (AiTM) kits. Each stands a phishing server between the victim and a real identity provider (predominantly Microsoft 365/Entra ID, plus Gmail, Google Workspace, and Okta), relays the victim's credentials and MFA response to the legitimate service in real time, and then captures the resulting authenticated session cookie. Because the attacker steals a post-MFA session token rather than a password, standard OTP/push MFA provides no protection — only phishing-resistant methods (FIDO2/WebAuthn) or immediate session/token revocation stop the takeover. Tycoon2FA was the dominant kit through most of 2025 (built by developer Saad Fridi, marketed via Telegram, ~2,000 subscribers, $120/10-days pricing), driving an estimated 96,000 distinct victims and 55,000+ compromised Microsoft accounts since 2023, and accounting for roughly 62% of all phishing Microsoft blocked by mid-2025. A Microsoft Digital Crimes Unit-led technical disruption, coordinated with Europol's Cyber Intelligence Extension Programme and law enforcement in Latvia, Lithuania, Portugal, Poland, Spain, and the UK, seized 330 domains forming the platform's control-panel and phishing-page infrastructure on March 4, 2026, under a U.S. District Court (SDNY) order. The operators rebuilt on new infrastructure within days and, by late April 2026, added device-code phishing to the kit — converging it with the newer EvilTokens technique described below. EvilProxy and Evilginx2 use the same AiTM mechanics against a broader identity-provider set (Microsoft 365, Okta, Google Workspace) at $150-600/month. Sneaky 2FA, tracked by Sekoia since December 2024 (campaigns dating to October 2024), is distributed through a fully automated Telegram bot and distinguishes itself with blurred real-Microsoft-interface decoy backgrounds and QR-code-based phishing lures.
The second, newer technique is represented by EvilTokens, first identified by Sekoia's Threat Detection & Research team in early March 2026 (circulating in underground channels since mid-February 2026). Rather than intercepting a password, EvilTokens abuses Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow: a phishing page impersonating a trusted service (Adobe, DocuSign, SharePoint) prompts the victim to copy a device code and complete authentication on Microsoft's genuine login page. Because the victim is authenticating to a real Microsoft URL, the flow bypasses the credential-phishing detections that catch fake-login-page kits. The attacker's backend then receives a short-lived access token and a 90-day rolling refresh token, converts it into a Primary Refresh Token for SSO hijacking, and can perform Graph API reconnaissance across the compromised tenant. Over 1,000 domains were hosting EvilTokens phishing pages by March 23, 2026, and the operator plans to expand targeting to Gmail and Okta.
Beyond enterprise identity, BlueKit is a newly observed AI-powered all-in-one PhaaS dashboard offering 40+ brand templates, automated domain registration, geolocation spoofing, antibot cloaking, and — as of its most recent update — browser-in-the-middle (BitM) session hijacking alongside an AI assistant and voice-cloning add-on. CryptoChameleon runs multi-channel (email/SMS/voice) social-engineering campaigns against cryptocurrency-exchange users and FCC employees, gating its phishing pages behind hCaptcha to block automated crawlers; its TTPs resemble the 2022 Oktapus/Scattered Spider campaign without confident attribution. Darcula (and its v3 darcula-suite evolution) is a Chinese-language PhaaS platform that automa
Weaknesses (CWE)
CWE-290, CWE-451
Target sectors: health, education, finance, government administration, cryptocurrency, retail, technology, nonprofit
Target regions: North America, Europe, Asia-Pacific, Global
Timeline
- Tycoon2FA AiTM phishing kit first emerges, later becoming the dominant PhaaS platform of 2025.
- ESET (WeLiveSecurity) documents the Telekopye Telegram-bot fraud toolkit, overlapping with Group-IB's tracked Classiscam activity.
- CryptoChameleon phishing kit reported targeting FCC employees and cryptocurrency-platform users (Coinbase, Binance, Kraken, Gemini) via email/SMS/voice phishing.
- Sekoia's Threat Detection & Research team identifies Sneaky 2FA as a distinct AiTM PhaaS kit; campaign activity traced back to October 2024.
- The Register/SpyCloud report the YYlaiyu Chinese-language PhaaS panel hosted across 2,158+ tracked domains, spoofing 97 brands.
- EvilTokens OAuth device-code phishing kit begins circulating in underground cybercrime communities, ahead of formal identification.
- Microsoft Digital Crimes Unit and Europol's Cyber Intelligence Extension Programme, with law enforcement in Latvia, Lithuania, Portugal, Poland, Spain, and the UK, seize 330 domains forming Tycoon2FA's core infrastructure under a U.S. District Court (SDNY) order.
- Sekoia's Threat Detection & Research team formally identifies EvilTokens as a widespread OAuth 2.0 Device Authorization Grant abuse kit; over 1,000 phishing domains observed by March 23, 2026.
- Tycoon2FA operators, having rebuilt infrastructure within days of the takedown, add device-code phishing to the kit — converging it with the EvilTokens technique.
- Google Threat Intelligence Group publishes analysis situating YYlaiyu within a broader, increasingly automated Chinese-language phishing ecosystem.
- Security researchers report BlueKit, a new AI-powered all-in-one PhaaS dashboard with 40+ brand templates and browser-in-the-middle session hijacking.
- SOCRadar publishes 'Top 10 Phishing Kits Used by Cybercriminals,' consolidating all ten platforms as currently active.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1598.003, T1598.004, T1583.001, T1583.006, T1566.002, T1566.001, T1660, T1204.001, T1036.005, T1027