Cybercriminals are increasingly adopting a subscription-based model, offering a wide range of crime-as-a-service (CaaS) tools and infrastructure that lower the barrier to entry for less skilled attackers. Services such as phishing-as-a-service (PhaaS) now provide turnkey solutions, including AI-powered tools like SpamGPT for generating convincing phishing emails and malicious document builders like MatrixPDF, all available for recurring fees. These platforms offer features such as customer support and user guides, making sophisticated attacks accessible to a broader audience. The ecosystem also includes the resale of compromised accounts and access, further fueling the underground economy.
Recent campaigns demonstrate the effectiveness and evolution of these services. For example, a targeted phishing operation used fake Calendly invites impersonating over 75 major brands to steal Google Workspace and Facebook business credentials, leveraging AI to craft highly convincing lures. Compromised ad manager accounts are then used for malvertising, malware distribution, and further phishing. Meanwhile, advanced adversary-in-the-middle (AiTM) frameworks like Evilginx are being deployed in attacks against educational institutions, bypassing multi-factor authentication and evading traditional detection methods. These developments highlight the growing sophistication and commercialization of cybercrime, with attackers exploiting both technical innovation and social engineering at scale.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers also linked the broader business-account phishing activity to malicious sponsored ads that spoofed Google login pages to target Google Ads Manager accounts. Compromised accounts could then be abused for malvertising, further phishing, malware delivery, or resale.
Analysis of the campaign revealed Browser-in-the-Browser techniques, adversary-in-the-middle phishing pages, CAPTCHAs, and anti-analysis controls such as blocking VPNs, proxies, and developer tools. These methods were used to improve credential theft success and bypass 2FA protections.
Researchers identified an ongoing phishing campaign using fake Calendly invites and recruiter lures to impersonate more than 75 major brands, including Disney, MasterCard, Uber, Unilever, and LVMH. The operation targeted Google Workspace, Facebook Business, and especially Google MCC ad manager accounts.
DNS-based analysis and fingerprinting uncovered 67 related domains and multiple dedicated IP addresses associated with the university phishing campaign. The findings provided actionable indicators of activity for defenders tracking the Evilginx-based operation.
During the university SSO campaign, the actor moved from using GoDaddy and NameCheap-hosted infrastructure to Cloudflare-proxied phishing domains. The change helped obscure the short-lived brand-impersonating sites used in the attacks.
From April 2025 onward, the threat actor broadened the campaign to at least 18 U.S. universities, with activity increasing mid-year and additional schools added over time. The most targeted institutions included UC Santa Cruz, UC Santa Barbara, the University of San Diego, Virginia Commonwealth University, and the University of Michigan.
Researchers observed the earliest known activity in a recurring phishing campaign against U.S. university single sign-on portals on April 12, 2025. The attackers used Evilginx adversary-in-the-middle phishing to steal credentials and session cookies and bypass MFA.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 83 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceblogs.infoblox.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.