phishing-as-a-service (PhaaS)
Coverage of phishing-as-a-service (PhaaS) in the Nexus archive.
- Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers disclosed a phishing-as-a-service (PhaaS) platform designed to strip Apple's Activation Lock from stolen devices. This system utilizes AI voice agents that call theft victims while impersonating Apple Support to obtain the device passcode. SOCRadar Threat Research Unit tracks this malicious platform, identifying it as AnonyMousKIT.
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing, which exploits the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and steal user tokens. This method allows attackers to seize control of accounts by leveraging a legitimate authentication protocol.
- FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
The FBI has issued a warning about the Kali365 phishing-as-a-service platform, which exploits OAuth device code authentication to hijack Microsoft 365 accounts. The service steals session tokens and bypasses multi-factor authentication (MFA), posing a significant cybersecurity threat.