Phishing  H  SPAM  PHISHING |  2026()  2025()  2024()  2023()  2022()

DATE

NAME

INFO

CATEGORY

SUBCATE

30.9.26

Zecurit RMM Zecurit RMM Abuse Demands Attention: DocuSign Phishing Delivers a Signed Agent PHISHING PHISHING

19.9.26

ORAX ORAX is a phishing-as-a-service (PhaaS) platform that uses WebSockets and live session control to capture MFA-authenticated Google Workspace sessions. PHISHING PHAAS

17.9.26

N0va Phishkit N0va Phishkit Targets North America and Europe Through Microsoft Logins PHISHING PHISHING KIT
27.8.26 USPS Smishing Kit The Package That Never Shipped: Following a USPS Smishing Kit Through Censys DNS Data PHISHING KIT
27.8.26 DOUBLOON DREDGER DOUBLOON DREDGER token harvesting: Notion abuse, EvilTokens, and a side of Tycoon2FA PHISHING KIT
27.8.26 Matrix Introducing Matrix: A Microsoft 365 AiTM Platform Overlapping the Sneaky2FA Lineage PHISHING KIT
27.8.26 iAuthFlow v2 iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets PHISHING KIT
27.8.26 ARToken ARToken: The Device Code Phishing Platform Built for Full Microsoft 365 Takeover PHISHING KIT
27.8.26 LinXcoded (Mirage2FA) LinXcoded (Mirage2FA): Microsoft 365 Phishing Platform Uses HTML Attachments to Steal Post-MFA Sessions PHISHING KIT
27.8.26 Blacksite Blacksite: New AiTM Phishing Kit Evades URL Scanners via Cloaked.gg PHISHING KIT
27.8.26 ZeroTokens ZeroTokens: Phishing Platform Gives Operators Real-Time Control of Attack Flow PHISHING KIT
27.8.26 Meet Bluekit Meet Bluekit: The AI-Powered All-in-One Phishing Kit PHISHING KIT
27.8.26 NovaCookies NovaCookies at scale: Inside the $320 Phishing Service Targeting Hundreds of Organizations PHISHING KIT
26.8.26 Balonx Sistema Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities. PHISHING PHaaS
26.8.26 p1bot Inside p1bot: A Vishing Platform Weaponizing ElevenLabs PHISHING VISHING
26.8.26 AnonyMousKIT Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain PHISHING PHaaS

5.8.26

Telegram-Distributed M365 AiTM PhaaS ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. PHISHING PhaaS

27.7.26

JIVS PhishKit Inside JIVS PhishKit: A Domain-Adaptive Credential Harvester PHISHING KIT

24.7.26

BlueNoroff ClickFix Kit JUMPSEC has obtained and analysed the source code behind an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings. Unlike previous reporting, this research provides source-level visibility into how the operation works after operators mistakenly exposed JavaScript source maps on live infrastructure. PHISHING KIT

18.7.26

Jalisco Toolkit The Jalisco Toolkit and AI-Powered Phishing Surge PHISHING TOOL
12.7.26 Forg365 Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365 PHISHING Phishing-as-a-service
29.6.26 Bluekit Phishing-as-a-Service Bluekit Phishing-as-a-Service: Browser-in-the-Middle, Evolved PHISHING Phishing-as-a-Service
12.6.26 Phishing for Lobsters Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets PHISHING PHISHING
30.5.26 ChatGPhish ChatGPhish: The Page Is the Payload PHISHING PHISHING
11.5.26 Legitimate “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security PHISHING PHISHING
3.5.26 Bluekit Meet Bluekit: The AI-Powered All-in-One Phishing Kit PHISHING KIT
2.5.26 AccountDumpling Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts PHISHING PHISHING
18.4.26 SessionShark SessionShark Steals Session Tokens to Slip Past Office 365 MFA PHISHING PHISHING KIT
2.4.26 Bubble Bubble: a new tool for phishing scams PHISHING TOOLS
3.3.26 Starkiller Starkiller: New Phishing Framework Proxies Real Login Pages to Bypass MFA PHISHING KIT
17.1.26 Mamba Phishing-as-a-Service Kit INTRODUCTION CYFIRMA assesses that Mamba 2FA is a representative of a broader class of adversary-in-the-middle phishing frameworks that have become increasingly prevalen PHISHING KIT
2.1.26 Phishing Campaign Leverages Trusted Google Cloud Automation Capabilities to Evade Detection This report describes a phishing campaign in which attackers impersonate legitimate Google generated messages by abusing Google Cloud Application Integration to distribute malicious emails that appear to originate from trusted Google infrastructure. PHISHING PHISHING