Phishing H SPAM PHISHING | 2026() 2025() 2024() 2023() 2022()
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
30.9.26 |
Zecurit RMM | Zecurit RMM Abuse Demands Attention: DocuSign Phishing Delivers a Signed Agent | PHISHING | PHISHING |
|
19.9.26 |
ORAX | ORAX is a phishing-as-a-service (PhaaS) platform that uses WebSockets and live session control to capture MFA-authenticated Google Workspace sessions. | PHISHING | PHAAS |
|
17.9.26 |
N0va Phishkit | N0va Phishkit Targets North America and Europe Through Microsoft Logins | PHISHING | PHISHING KIT |
| 27.8.26 | USPS Smishing Kit | The Package That Never Shipped: Following a USPS Smishing Kit Through Censys DNS Data | PHISHING | KIT |
| 27.8.26 | DOUBLOON DREDGER | DOUBLOON DREDGER token harvesting: Notion abuse, EvilTokens, and a side of Tycoon2FA | PHISHING | KIT |
| 27.8.26 | Matrix | Introducing Matrix: A Microsoft 365 AiTM Platform Overlapping the Sneaky2FA Lineage | PHISHING | KIT |
| 27.8.26 | iAuthFlow v2 | iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets | PHISHING | KIT |
| 27.8.26 | ARToken | ARToken: The Device Code Phishing Platform Built for Full Microsoft 365 Takeover | PHISHING | KIT |
| 27.8.26 | LinXcoded (Mirage2FA) | LinXcoded (Mirage2FA): Microsoft 365 Phishing Platform Uses HTML Attachments to Steal Post-MFA Sessions | PHISHING | KIT |
| 27.8.26 | Blacksite | Blacksite: New AiTM Phishing Kit Evades URL Scanners via Cloaked.gg | PHISHING | KIT |
| 27.8.26 | ZeroTokens | ZeroTokens: Phishing Platform Gives Operators Real-Time Control of Attack Flow | PHISHING | KIT |
| 27.8.26 | Meet Bluekit | Meet Bluekit: The AI-Powered All-in-One Phishing Kit | PHISHING | KIT |
| 27.8.26 | NovaCookies | NovaCookies at scale: Inside the $320 Phishing Service Targeting Hundreds of Organizations | PHISHING | KIT |
| 26.8.26 | Balonx Sistema | Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities. | PHISHING | PHaaS |
| 26.8.26 | p1bot | Inside p1bot: A Vishing Platform Weaponizing ElevenLabs | PHISHING | VISHING |
| 26.8.26 | AnonyMousKIT | Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain | PHISHING | PHaaS |
|
5.8.26 |
Telegram-Distributed M365 AiTM PhaaS | ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. | PHISHING | PhaaS |
|
27.7.26 |
JIVS PhishKit | Inside JIVS PhishKit: A Domain-Adaptive Credential Harvester | PHISHING | KIT |
|
24.7.26 |
BlueNoroff ClickFix Kit | JUMPSEC has obtained and analysed the source code behind an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings. Unlike previous reporting, this research provides source-level visibility into how the operation works after operators mistakenly exposed JavaScript source maps on live infrastructure. | PHISHING | KIT |
|
18.7.26 |
Jalisco Toolkit | The Jalisco Toolkit and AI-Powered Phishing Surge | PHISHING | TOOL |
| 12.7.26 | Forg365 | Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365 | PHISHING | Phishing-as-a-service |
| 29.6.26 | Bluekit Phishing-as-a-Service | Bluekit Phishing-as-a-Service: Browser-in-the-Middle, Evolved | PHISHING | Phishing-as-a-Service |
| 12.6.26 | Phishing for Lobsters | Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets | PHISHING | PHISHING |
| 30.5.26 | ChatGPhish | ChatGPhish: The Page Is the Payload | PHISHING | PHISHING |
| 11.5.26 | Legitimate | “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security | PHISHING | PHISHING |
| 3.5.26 | Bluekit | Meet Bluekit: The AI-Powered All-in-One Phishing Kit | PHISHING | KIT |
| 2.5.26 | AccountDumpling | Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts | PHISHING | PHISHING |
| 18.4.26 | SessionShark | SessionShark Steals Session Tokens to Slip Past Office 365 MFA | PHISHING | PHISHING KIT |
| 2.4.26 | Bubble | Bubble: a new tool for phishing scams | PHISHING | TOOLS |
| 3.3.26 | Starkiller | Starkiller: New Phishing Framework Proxies Real Login Pages to Bypass MFA | PHISHING | KIT |
| 17.1.26 | Mamba Phishing-as-a-Service Kit | INTRODUCTION CYFIRMA assesses that Mamba 2FA is a representative of a broader class of adversary-in-the-middle phishing frameworks that have become increasingly prevalen | PHISHING | KIT |
| 2.1.26 | Phishing Campaign Leverages Trusted Google Cloud Automation Capabilities to Evade Detection | This report describes a phishing campaign in which attackers impersonate legitimate Google generated messages by abusing Google Cloud Application Integration to distribute malicious emails that appear to originate from trusted Google infrastructure. | PHISHING | PHISHING |