
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and session tokens, effectively neutralizing standard multi-factor authentication (MFA) protections. Each kit uses a fundamentally different technical approach: Adversary-in-the-Middle (AiTM) session hijacking, OAuth device-code abuse, and real-time reverse-proxy credential relay, but all three converge on the […]
The post Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA appeared first on Cyber Security News.