Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
Global phishing-as-a-service (PhaaS) activity surged to 7,295 tracked uploads during the week of July 20-26, 2026, driven overwhelmingly by OAuth device-code flow abuse and adversary-in-the-middle (AiTM) kits targeting Microsoft 365 identities.
Cybercriminal group Storm-1747, the operator behind Tycoon2FA, logged 50 attributed uploads, down 6 from the prior week following ongoing law-enforcement pressure on its infrastructure.
The data below is sourced from ANY.RUN’s weekly Threat Intelligence Lookup snapshot and cross-referenced against vendor research from Microsoft, Sekoia, Push Security, Barracuda, and The Hacker News.
| Category | Total Uploads | Weekly Change |
| OAuth Flow Phishing | 2,446 | +194 |
| Suspected Quishing (QR phishing) | 974 | -17 |
| PDF-based lures | 536 | -111 |
| Malicious URLs | 229 | -67 |
| Storm-1747 (cybercriminal group) | 50 | -6 |
The rise in OAuth flow phishing (+194) confirms that device-code authentication abuse has overtaken classic credential-harvesting pages as the primary AiTM technique this week, a trend flagged repeatedly by Microsoft, Push Security, and LevelBlue through Q2-Q3 2026.
| Rank | Kit Name | Total Uploads | Weekly Change | Primary Technique |
| 1 | Sneaky2FA | 886 | -303 | AiTM reverse proxy, Telegram PhaaS |
| 2 | EvilTokens | 684 | +65 | OAuth device-code phishing |
| 3 | Evilginx2/EvilProxy | 660 | -199 | Reverse-proxy AiTM, cookie theft |
| 4 | Kali365 | 503 | +17 | Device-code token theft |
| 5 | MassBass | 90 | -19 | Emerging PhaaS credential harvester |
| 6 | Greatness | 88 | +30 | M365 AiTM proxy, MFA/TOTP bypass |
| 7 | Kratos | 76 | -4 | AiTM session-cookie theft (post-takedown remnants) |
| 8 | Tycoon2FA | 46 | -11 | AiTM reverse proxy, Storm-1747 |
| 9 | Cephas | 27 | -79 | Obfuscated anti-bot AiTM kit |
Nine named kits are tracked individually in the source data; “OAuth Flow Phishing” and “Suspected Quishing” are broader technique categories that overlap with several of the kits above, particularly EvilTokens and Kali365.
Sneaky2FA is a full-featured, Telegram-sold PhaaS platform first detected in October 2024 that specifically compromises Microsoft 365 accounts via AiTM reverse-proxy interception.
It validates stolen credentials in real time against legitimate Microsoft APIs, uses blurred screenshots of real Microsoft interfaces as decoy backgrounds, and employs browser-in-the-browser fake login windows to defeat sandbox detection.
Despite the largest weekly decline of any kit (-303), it remains the single most-used phishing kit this week.
EvilTokens is a rapidly growing PhaaS kit that abuses the OAuth 2.0 device authorization grant flow, letting attackers hijack a legitimate, MFA-verified Microsoft 365 login without ever touching a password.
Delivered through Telegram bots, it bundles token harvesting, email harvesting, reconnaissance, and AI-driven lure generation, and has already been used in a March 2026 campaign against more than 340 organizations.
Its recon phase runs 10-15 days ahead of the actual phishing attempt, making early detection critical.
Evilginx2 is an open-source, red-team-turned-criminal reverse-proxy framework, while EvilProxy is its commercialized PhaaS derivative sold from $150-$400/month on dark web forums.
Both intercept live traffic between victims and real identity providers (Microsoft 365, Okta, Google Workspace) to harvest session cookies post-MFA.
Kali365, first observed in April 2026 and subject to an FBI advisory, is a subscription PhaaS kit (US$250/month or US$2,000/year) that steals Microsoft 365 access tokens via device-code phishing, entirely bypassing password entry and MFA prompts.
Victims approve what looks like a document-share or Teams-invite code on a genuine Microsoft URL, unknowingly authorizing the attacker’s session.
MassBass is tracked by ANY.RUN as an emerging phishing-kit family within the current AiTM/PhaaS wave; while public vendor writeups are limited compared to the larger kits, its inclusion in this week’s top-10 by upload volume indicates active criminal adoption for credential and session harvesting.
Active since November 2022, Greatness is a mature PhaaS tool with MFA bypass, IP filtering, and Telegram bot integration, focused exclusively on Microsoft 365 phishing pages.
It pre-fills the victim’s email address and injects the target company’s real logo and background, making it especially convincing for business users.
Campaigns concentrate on manufacturing, healthcare, and technology firms in the US, UK, Australia, South Africa, and Canada.
Kratos was dismantled by German (BKA/ZIT) and US law enforcement in July 2026, with over 200 servers seized and its alleged Indonesian developer arrested; investigators estimate 1,800 paying customers ran roughly 15,000 monthly campaigns.
Despite the takedown, residual activity (76 uploads, -4) persists because the kit code remains in criminal hands. Kratos harvested both credentials and session cookies, defeating MFA entirely.
Tycoon2FA, operated by threat actor Storm-1747, has been the dominant global AiTM PhaaS platform since August 2023, at its peak responsible for an estimated 44.5% of all credential-theft attacks and 89% of the AiTM PhaaS market in 2025.
A 2026 law-enforcement disruption reduced its footprint, and this week’s -11 change reflects continued decay, though Barracuda notes the ecosystem has redistributed rather than disappeared.
Cephas, first seen in August 2024, is an obfuscated AiTM kit notable for embedding random invisible characters and astronomy/bible-themed code comments to evade YARA-rule and pattern-based detection.
It validates stolen credentials and session tokens directly against Microsoft APIs during submission and logged the sharpest weekly drop (-79) among named kits this week.
| Industry | Kits Observed Targeting It |
| Finance & Insurance | EvilTokens, Tycoon2FA, Kratos |
| Manufacturing | Greatness, Tycoon2FA |
| Healthcare | Greatness |
| Technology / SaaS | Sneaky2FA, Evilginx2/EvilProxy, Tycoon2FA |
| Government / Defense | Tycoon2FA |
| HR, Logistics, Sales (functional targeting) | EvilTokens |
| Indicator | Associated Kit |
| authdocspro[.]com | EvilTokens |
| backdoor-hub[.]com | EvilTokens |
| bumpgames[.]net | EvilTokens |
| carbatterygurgaon[.]com | EvilTokens |
| careldutoit-el[.]co[.]za | EvilTokens |
| dao[.]com[.]au | EvilTokens |
| docusend[.]net | EvilTokens |
| ssolutionmail[.]com | EvilTokens |
| eqfit[.]co[.]za | EvilTokens |
| eventcalender-schedule[.]com | EvilTokens |
| evobothub[.]org | EvilTokens |
| m365-verification[.]ru | Tycoon2FA |
| authportal-gmail[.]org | Tycoon2FA |
| tycoonkit-login[.]su | Tycoon2FA |
| evilproxy[.]pro | EvilProxy |
| top-cyber[.]club | EvilProxy |
| rproxy[.]io / login-live.rproxy[.]io | EvilProxy |
| msdnmail[.]net | EvilProxy |
| dwbud[.]vilaribit[.]com | Kratos-family kit |
| api[.]telegram[.]org (exfil endpoint) | Multiple PhaaS kits (Telegram C2) |
| geoplugin[.]net (victim geolocation) | Kratos-family kit |
| Indicator | Associated Kit |
| /cllascio.php | Tycoon2FA |
| /PTT/SOft | Kratos-family kit |
| next.php, save.php (credential POST endpoints) | Kratos |
| barr.svg, lg.svg (paired login-page assets, 90% detection recall) | Kratos |
| Indicator | Associated Kit |
| 147[.]78[.]47[.]250 | EvilProxy |
| 185[.]158[.]251[.]169 | EvilProxy |
| 194[.]76[.]226[.]166 | EvilProxy |
| 185.231.204.77 | Tycoon2FA |
| 193.124.182.69 | Tycoon2FA |
| 41.128.0.142 (Egypt-based relay origin) | Kratos-family kit |
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…