Phishing-as-a-service platforms continued to industrialize account takeover operations, with kits such as Tycoon2FA, EvilProxy, Sneaky 2FA, CryptoChameleon, Darcula, Evilginx, and EvilTokens enabling attackers to steal credentials, session cookies, MFA responses, payment-card data, and OAuth tokens at scale. Reporting across 2025 and 2026 described more than a million PhaaS attacks in a two-month period, a possible CryptoChameleon social-engineering campaign targeting LastPass and cryptocurrency users, and a targeted adversary-in-the-middle campaign against RBC Express online banking customers that used malvertising and cloaking to bypass multi-factor authentication.
Researchers also documented a shift from fake login pages toward token theft and abuse of legitimate authentication workflows. A July 2026 analysis tied a bulk phishing platform dubbed Mailer-Go Mission Control to EvilTokens operations abusing Microsoft's OAuth device-code flow, while sector reporting said AiTM phishing had become the top initial access vector for law firms, with Tycoon2FA responsible for over half of AiTM-related compromises in that sector during 2025 despite a March 2026 disruption. The combined reporting warned that modern phishing kits lower the barrier to entry with automation, domain management, and real-time victim interaction, and recommended phishing-resistant MFA such as FIDO2/WebAuthn, conditional access, managed-device controls, and rapid revocation of compromised sessions and refresh tokens.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
By 2026-06-10, Fortinet classified healthprofessionals21[.]org as phishing and ESET flagged it as suspicious. The domain had been used as cover infrastructure for Mailer-Go tracking subdomains in a phishing chain leading to EvilTokens.
SOCRadar disclosed The Quarry in June 2026 as a modular phishing and malware-as-a-service operation. It linked more than 80 domains, over 40 ScreenConnect panels, and more than 500 victim IP addresses across 14 countries to the ecosystem, and assessed that it included a modified credential-harvesting panel possibly derived from Evilginx.
The domains coldchain-distribution[.]com and healthprofessionals21[.]org, later tied to a Mailer-Go Mission Control phishing campaign, were both registered on 2026-06-01. The campaign ultimately routed victims to a Cloudflare Workers page running EvilTokens to abuse Microsoft's OAuth device-code flow.
Group-IB reported in March 2026 a large fake-shipment phishing campaign targeting consumers across the Middle East and Africa using infrastructure with characteristics associated with Darcula. The phishing pages used persistent WebSocket connections to send victims' personal data, payment-card details, and one-time passwords to attacker-controlled servers.
Microsoft, Europol, Cloudflare, and other partners disrupted Tycoon2FA in March 2026. The operation seized 330 domains supporting the phishing service's infrastructure.
Researchers documented Browser-in-the-Browser functionality in the Sneaky 2FA phishing kit in November 2025. The kit was also described as an active Microsoft 365-focused AiTM platform distributed through the Telegram-based Sneaky Log service.
LastPass warned customers in October 2025 about a social-engineering campaign it assessed as possibly associated with CryptoChameleon, also tracked as UNC5356. The company identified passkey-themed domains including mypasskey[.]info and passkeysetup[.]com in the activity.
SOCRadar said The Quarry, a modular phishing and malware-as-a-service operation, had been active since at least April 2025. The ecosystem included phishing kits, cloaking infrastructure, bulk email tools, remote access panels, and post-exploitation scripts sold to nearly 200 operators.
Barracuda detected more than one million phishing-as-a-service attacks during January and February 2025. In January 2025, Tycoon 2FA accounted for 89% of detected incidents, with EvilProxy at 8% and Sneaky 2FA at 3%.
Tycoon2FA emerged in 2023 as a major adversary-in-the-middle phishing service targeting Microsoft 365, Gmail, and other cloud accounts. It proxied logins to capture credentials, MFA responses, and authenticated session cookies.
ThreatLabz said it observed a sharp increase in a large-scale adversary-in-the-middle phishing campaign targeting enterprise users of Microsoft email services beginning in June 2022. The operation used newly registered phishing domains, redirector chains, browser fingerprinting and cloaking, and a custom proxy-based kit to bypass MFA and steal Microsoft account sessions.
Resecurity reported that EvilProxy, also referred to as Moloch, first appeared in early May 2022 as a phishing-as-a-service platform advertised on underground forums. The service used reverse-proxy and cookie-injection techniques to bypass MFA and hijack authenticated sessions, initially targeting Google and Microsoft users.
After Cloudflare marked Robin Banks domains as malicious, the phishing-as-a-service platform reportedly suffered a roughly three-day disruption in 2022, then moved infrastructure to DDOS-GUARD and tightened operational security. IronNet also reported that after its earlier July 2022 coverage, Robin Banks introduced a paid cookie-stealing add-on derived from evilginx2 with phishlets for Google, Yahoo, and Outlook to bypass MFA.
Confiant described a lower-volume, targeted phishing campaign against RBC Express Online Banking using an automated adversary-in-the-middle relay kit. The operation was intended to harvest credentials, bypass MFA, and was distributed through cloaked malvertising.
eSentire reported that adversary-in-the-middle phishing had become the most common initial access method against law firms, accounting for 28.57% of such events. The report said Tycoon2FA drove 52.3% of AiTM-related account compromises in the legal sector across 2025 and that activity rebounded quickly after the March 2026 disruption.
Gen published research on a phishing campaign using the previously undocumented Mailer-Go Mission Control platform for delivery and tracking, with the final stage handled by EvilTokens via Microsoft's OAuth device-code flow. The report highlighted single-use recipient links, burned tracking URLs, and fallback redirects to legitimate Visa domains to hinder analysis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcesocradar.io
Open sourceinfosecurity-magazine.com
Open sourcegendigital.com
Open sourcedeveloper.mozilla.org
Open sourceironnet.com
Open sourceattack.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.