Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)
Top Phishing-Kit Platforms Driving AiTM Session-Theft and (TL-2026-2024), also tracked as Tycoon 2FA, is a high-severity phishing campaign, first published 2026-08-15. It has no confirmed attribution, affects Microsoft Microsoft 365 / Entra ID (Outlook, SharePoint, OneDrive, maps to 18 MITRE ATT&CK techniques (T1027, T1036.005, T1056.003), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-2024
- Threat ID
- TL-2026-2024
- Also known as
- Tycoon 2FA, EvilProxy, Evilginx2, Sneaky 2FA, EvilTokens, BlueKit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-15
- Last reviewed
- 2026-08-15
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- health, education, finance, government administration, cryptocurrency, retail, technology, nonprofit
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Top Phishing-Kit Platforms Driving AiTM Session-Theft and
Malware and tooling: BlueKit, CryptoChameleon, Darcula / darcula-suite, EvilTokens, Evilginx2 / EvilProxy, Sneaky 2FA, Telekopye / Classiscam, Tycoon2FA, X-Antibot-Token, YYlaiyu, evilginx2 - S9003
SOCRadar's August 12, 2026 roundup profiles ten active phishing-as-a-service (PhaaS) platforms — Tycoon2FA, EvilProxy/Evilginx2, Sneaky 2FA, EvilTokens, BlueKit, CryptoChameleon, Darcula/darcula-suite, YYlaiyu, and Telekopye — that package adversary-in-the-middle (AiTM) session-cookie theft, OAuth device-code token theft, and smishing/vishing consumer fraud into subscription products. The most consequential single development is Tycoon2FA's survival of a March 4, 2026 Microsoft/Europol takedown (330 domains seized across six countries) and its late-April 2026 addition of device-code phishing.
How Top Phishing-Kit Platforms Driving AiTM Session-Theft and works
This threat aggregates ten commercially available phishing-kit platforms that SOCRadar identified as currently active and responsible for the bulk of enterprise-identity and consumer phishing traffic as of August 2026. The kits split into two operational families.
The first family — Tycoon2FA, EvilProxy (the commercialized fork of the open-source Evilginx2), and Sneaky 2FA — are reverse-proxy adversary-in-the-middle (AiTM) kits. Each stands a phishing server between the victim and a real identity provider (predominantly Microsoft 365/Entra ID, plus Gmail, Google Workspace, and Okta), relays the victim's credentials and MFA response to the legitimate service in real time, and then captures the resulting authenticated session cookie. Because the attacker steals a post-MFA session token rather than a password, standard OTP/push MFA provides no protection — only phishing-resistant methods (FIDO2/WebAuthn) or immediate session/token revocation stop the takeover. Tycoon2FA was the dominant kit through most of 2025 (built by developer Saad Fridi, marketed via Telegram, ~2,000 subscribers, $120/10-days pricing), driving an estimated 96,000 distinct victims and 55,000+ compromised Microsoft accounts since 2023, and accounting for roughly 62% of all phishing Microsoft blocked by mid-2025. A Microsoft Digital Crimes Unit-led technical disruption, coordinated with Europol's Cyber Intelligence Extension Programme and law enforcement in Latvia, Lithuania, Portugal, Poland, Spain, and the UK, seized 330 domains forming the platform's control-panel and phishing-page infrastructure on March 4, 2026, under a U.S. District Court (SDNY) order. The operators rebuilt on new infrastructure within days and, by late April 2026, added device-code phishing to the kit — converging it with the newer EvilTokens technique described below. EvilProxy and Evilginx2 use the same AiTM mechanics against a broader identity-provider set (Microsoft 365, Okta, Google Workspace) at $150-600/month. Sneaky 2FA, tracked by Sekoia since December 2024 (campaigns dating to October 2024), is distributed through a fully automated Telegram bot and distinguishes itself with blurred real-Microsoft-interface decoy backgrounds and QR-code-based phishing lures.
The second, newer technique is represented by EvilTokens, first identified by Sekoia's Threat Detection & Research team in early March 2026 (circulating in underground channels since mid-February 2026). Rather than intercepting a password, EvilTokens abuses Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow: a phishing page impersonating a trusted service (Adobe, DocuSign, SharePoint) prompts the victim to copy a device code and complete authentication on Microsoft's genuine login page. Because the victim is authenticating to a real Microsoft URL, the flow bypasses the credential-phishing detections that catch fake-login-page kits. The attacker's backend then receives a short-lived access token and a 90-day rolling refresh token, converts it into a Primary Refresh Token for SSO hijacking, and can perform Graph API reconnaissance across the compromised tenant. Over 1,000 domains were hosting EvilTokens phishing pages by March 23, 2026, and the operator plans to expand targeting to Gmail and Okta.
Beyond enterprise identity, BlueKit is a newly observed AI-powered all-in-one PhaaS dashboard offering 40+ brand templates, automated domain registration, geolocation spoofing, antibot cloaking, and — as of its most recent update — browser-in-the-middle (BitM) session hijacking alongside an AI assistant and voice-cloning add-on. CryptoChameleon runs multi-channel (email/SMS/voice) social-engineering campaigns against cryptocurrency-exchange users and FCC employees, gating its phishing pages behind hCaptcha to block automated crawlers; its TTPs resemble the 2022 Oktapus/Scattered Spider campaign without confident attribution. Darcula (and its v3 darcula-suite evolution) is a Chinese-language PhaaS platform that automates cloning of any brand's website via headless-Chrome browser automation, primarily supporting SMS-based (smishing) package-delivery and financial-fraud lures; it has been linked to 90,000+ detected phishing domains and over 800,000 claimed victims. YYlaiyu, documented by Google's Threat Intelligence Group in May 2026 as part of the broader Chinese-language phishing ecosystem, has offered 400+ localized templates since November 2025 across 119 countries with a Japan-specific focus (Amazon, Rakuten, PayPay, JR Rail, etc.), and is tracked across 2,158+ domains as of October 2025. Telekopye (tracked by Group-IB as overlapping with Classiscam) is a Telegram-bot-driven fraud toolkit that lets low-skilled operators ('Neanderthals') run online-marketplace seller/buyer/refund scams, generating phishing pages and fake screenshots on demand.
Collectively these platforms illustrate that phishing-resistant MFA (FIDO2/WebAuthn passkeys) and Conditional Access controls restricting the OAuth device-code flow are now the only reliable mitigations against enterprise-identity phishing; OTP and push-based MFA are routinely defeated at scale by commodity, subscription-priced criminal tooling.
MITRE ATT&CK techniques used in TL-2026-2024
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1684.001 Impersonation
Credential Access
T1056.003 Input Capture: Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1187 Forced Authentication; T1528 Steal Application Access Token
Execution
T1204.001 User Execution: Malicious Link
credential-access
T1539 Steal Web Session Cookie
lateral-movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Collection
Initial Access
T1566.001 Phishing: Spearphishing Attachment; T1566.002 Phishing: Spearphishing Link; T1660 Phishing
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services
Reconnaissance
T1598.003 Phishing for Information: Spearphishing Link; T1598.004 Phishing for Information: Spearphishing Voice
Affected products and versions in Top Phishing-Kit Platforms Driving AiTM Session-Theft and
- Microsoft — Microsoft 365 / Entra ID (Outlook, SharePoint, OneDrive, Teams, Azure Management, Graph API)
Vulnerable versions: Accounts protected only by OTP/push MFA (not phishing-resistant FIDO2/WebAuthn)
Fixed in: Accounts enforcing FIDO2/WebAuthn security keys or Conditional Access token-protection policies - Google — Gmail / Google Workspace
Vulnerable versions: Accounts protected only by OTP/push MFA
Fixed in: Accounts enforcing phishing-resistant MFA - Okta — Okta Identity Cloud
Vulnerable versions: Accounts protected only by OTP/push MFA
Fixed in: Accounts enforcing FIDO2/WebAuthn - Apple — iCloud
Vulnerable versions: Accounts targeted by CryptoChameleon SMS/voice phishing - Multiple — Cryptocurrency exchanges (Coinbase, Binance, Kraken, Gemini)
Vulnerable versions: Employee and user accounts targeted by CryptoChameleon multi-channel phishing - Multiple — 200+ consumer/enterprise brands cloned on demand (Darcula-suite 3.0 any-brand cloning; YYlaiyu 400+ templates incl. Amazon, Apple, PayPay, Rakuten; BlueKit 40+ templates)
Vulnerable versions: Any brand's public login or checkout page can be cloned on demand via automated browser-based tooling
Remediation for Top Phishing-Kit Platforms Driving AiTM Session-Theft and
Patches
- No vendor software patch applies — these are criminal PhaaS platforms abusing legitimate authentication flows, not software vulnerabilities; the Microsoft/Europol March 2026 domain seizure (330 domains) is the primary law-enforcement disruption to date
Immediate actions
- Block identified Tycoon2FA, EvilTokens, and Darcula-suite phishing domains/subdomains (including the *-s-account.workers.dev Cloudflare Workers pattern) at DNS/web proxy
- Revoke and force re-authentication of any account that completed sign-in through a suspected AiTM proxy or device-code phishing page; explicitly invalidate active sessions and refresh tokens, since password reset alone does not stop a stolen session cookie or OAuth token
- Alert users to Microsoft's device-code warning ('Do not enter codes from sources you don't trust') and, where the device code flow is not required for business operations, block it via Conditional Access authentication flow policies
Workarounds
- Enforce phishing-resistant MFA (FIDO2/WebAuthn) as the primary compensating control since OTP/push MFA is bypassable by all AiTM kits profiled here
- Disable or tightly restrict legacy/device-code OAuth flows for Microsoft 365 tenants that do not operationally require them
Longer-term hardening
- Migrate MFA for privileged and high-risk accounts to phishing-resistant methods (FIDO2/WebAuthn hardware keys or platform passkeys) — every AiTM kit in this roundup defeats OTP and push MFA
- Enforce Conditional Access token-protection/session-binding policies so stolen session cookies cannot be replayed from a new device or IP
- Restrict the OAuth 2.0 Device Authorization Grant to managed/compliant devices via Conditional Access
- Deploy anti-phishing email security tuned for QR-code, PDF, and calendar-invite lures given the diversification seen across Tycoon2FA, EvilTokens, and BlueKit distribution
Weaknesses (CWE) in Top Phishing-Kit Platforms Driving AiTM Session-Theft and
CWE-290, CWE-451
Timeline of Top Phishing-Kit Platforms Driving AiTM Session-Theft and
- Tycoon2FA AiTM phishing kit first emerges, later becoming the dominant PhaaS platform of 2025.
- ESET (WeLiveSecurity) documents the Telekopye Telegram-bot fraud toolkit, overlapping with Group-IB's tracked Classiscam activity.
- CryptoChameleon phishing kit reported targeting FCC employees and cryptocurrency-platform users (Coinbase, Binance, Kraken, Gemini) via email/SMS/voice phishing.
- Sekoia's Threat Detection & Research team identifies Sneaky 2FA as a distinct AiTM PhaaS kit; campaign activity traced back to October 2024.
- The Register/SpyCloud report the YYlaiyu Chinese-language PhaaS panel hosted across 2,158+ tracked domains, spoofing 97 brands.
- EvilTokens OAuth device-code phishing kit begins circulating in underground cybercrime communities, ahead of formal identification.
- Microsoft Digital Crimes Unit and Europol's Cyber Intelligence Extension Programme, with law enforcement in Latvia, Lithuania, Portugal, Poland, Spain, and the UK, seize 330 domains forming Tycoon2FA's core infrastructure under a U.S. District Court (SDNY) order.
- Sekoia's Threat Detection & Research team formally identifies EvilTokens as a widespread OAuth 2.0 Device Authorization Grant abuse kit; over 1,000 phishing domains observed by March 23, 2026.
- Tycoon2FA operators, having rebuilt infrastructure within days of the takedown, add device-code phishing to the kit — converging it with the EvilTokens technique.
- Google Threat Intelligence Group publishes analysis situating YYlaiyu within a broader, increasingly automated Chinese-language phishing ecosystem.
- Security researchers report BlueKit, a new AI-powered all-in-one PhaaS dashboard with 40+ brand templates and browser-in-the-middle session hijacking.
- SOCRadar publishes 'Top 10 Phishing Kits Used by Cybercriminals,' consolidating all ten platforms as currently active.
Sources cited for Top Phishing-Kit Platforms Driving AiTM Session-Theft and
- Top 10 Phishing Kits Used by Cybercriminals
- Defending the gates: How a global coalition disrupted Tycoon 2FA
- Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks
- Tycoon 2FA: an in-depth analysis of the latest version of the AiTM phishing kit
- New widespread EvilTokens kit: device code phishing as-a-service (Part 1)
- The Bleeding Edge of Phishing: darcula-suite 3.0 Enables DIY Phishing of Any Brand
- Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
- Most popular phishing kits used in 2026
- Researchers discover new all-in-one 'Bluekit' phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands
- Phishing kit YYlaiyu impersonates 97 brands for fraud
- More Than Meets the YY: Analyzing the YYlaiyu PhaaS Panel
- Telekopye: Hunting Mammoths using Telegram bot
- CryptoChameleon Attackers Target Apple, Okta Users
- Hackers target FCC, crypto firms in advanced Okta phishing attacks
- The Evolution of Chinese-Language Phishing Services
Threats related to Top Phishing-Kit Platforms Driving AiTM Session-Theft and
- EvilTokens Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication with AES-GCM "Ghost Code" to Breach Finance, Tech, and Managed Security Firms
- ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens PhaaS)
- 2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu, Lighthouse, Lucid, Smishing Triad)
- ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate)
- Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)
- TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms
Detection coverage for TL-2026-2024
As of 2026-08-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2024 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.