๐Ÿšจ Greatness #PhaaS turns a fake Microsoft 365 login page into a potential BEC, data theft, and payment fraud incident.

๐Ÿ‘จโ€๐Ÿ’ป Learn how its branded lures, MFA bypass capabilities, and credential theft workflows put business identities at risk: https://any.run/malware-trends/greatness/?utm_source=mastodon&utm_medium=post&utm_campaign=greatness_mtt&utm_term=220626&utm_content=linktomtt

FBI nimmt Phishing-as-a-Service-Plattform โ€žOutsiderโ€œ hops

Der Phishing-as-a-Service-Dienst โ€žOutsiderโ€œ wurde vom FBI vom Netz genommen. Auf tausenden Domains stahl er Millionen Kreditkarten.

heise online
INTERPOL Dismantles Sniper Dz Phishing-as-a-Service

According to Group-IB, an international operation led by INTERPOL has resulted in the dismantling of Sniper Dz, a phishing-as-a-service (PhaaS) platform that

CyberSecureFox

๐Ÿ“ฃ๐Ÿšจ๐ŸชGroup-IB, INTERPOL and Algerian Police have dismantled a decade-old Phishing-as-a-Service (#PhaaS) Network called #SniperDZ, known for providing ready-made login pages to steal credentials. Its alleged developer has been arrested as well.

Read: https://hackread.com/authorities-dismantle-sniperdz-phishing-network/

#CyberSecurity #CyberCrime #Phishing #Algeria #Interpol

Authorities Dismantle Decade-Old SniperDZ Phishing Network

Group-IB, INTERPOL and Algerian Police dismantle decade-old SniperDZ phishing network used to steal credentials, with its alleged developer arrested.

Hackread - Cybersecurity News, Data Breaches, AI and More

๐Ÿšจ ๐—ข๐—”๐˜‚๐˜๐—ต ๐—ง๐—ผ๐—ธ๐—ฒ๐—ป ๐—”๐—ฏ๐˜‚๐˜€๐—ฒ ๐—œ๐˜€ ๐—š๐—ฟ๐—ผ๐˜„๐—ถ๐—ป๐—ด: ๐—š๐—ฟ๐—ฒ๐—ฎ๐˜๐—ป๐—ฒ๐˜€๐˜€ ๐—ฅ๐—ฒ๐˜๐˜‚๐—ฟ๐—ป๐˜€ ๐˜„๐—ถ๐˜๐—ต ๐——๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—–๐—ผ๐—ฑ๐—ฒ ๐—ฃ๐—ต๐—ถ๐˜€๐—ต๐—ถ๐—ป๐—ด
We've identified renewed activity associated with the Greatness #PhaaS, which combines #AiTM and Device Code #Phishing to target Microsoft 365 Accounts.

โš ๏ธ Device Code Phishing abuses Microsoft's legitimate device authorization flow to obtain access tokens without directly collecting passwords or MFA codes. This shifts risk from credential theft to token abuse, reducing traditional phishing indicators for SOC teams to detect and investigate.

โ—๏ธ Greatness promotes token- and cookie-based access to Microsoft 365 accounts through its Telegram channel, advertising passwordless and code-less account compromise scenarios.

Observed capabilities include:
๐Ÿ”น Device Code Phishing for M365 token theft
๐Ÿ”น Phishing templates impersonating DocuSign, OneDrive, Outlook, and Voicemail
๐Ÿ”น Country-targeted login lures
๐Ÿ”น Cloudflare-hosted phishing links
๐Ÿ”น Keyword-based targeting engine
๐Ÿ”น Centralized administration panel

๐Ÿ‘จโ€๐Ÿ’ป Review the analysis session, investigate the phishing flow, and validate detection coverage: https://app.any.run/tasks/dd97835c-8a07-4917-ba23-cb8d8493b174/?utm_source=mastodon&utm_medium=post&utm_campaign=greatness_phaas&utm_term=100626&utm_content=linktoservice

๐Ÿ” Track Device Code Phishing activity associated with Greatness and uncover related infrastructure in #ANYRUN TI Lookup: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=greatness_phaas&utm_content=linktotilookup&utm_term=100626#%7B%22query%22:%22threatName:%5C%22greatness%5C%22%20and%20threatName:%5C%22oauth-ms-phish%5C%22%22,%22dateRange%22:180%7D

๐Ÿš€ Strengthen phishing detection and accelerate response across your SOC with #ANYRUN: https://any.run/phishing/?utm_source=mastodon&utm_medium=post&utm_campaign=greatness_phaas&utm_term=100626&utm_content=linktophishinglanding

#cybersecurity #infosec

Kali365-Phishing-Dienst kompromittiert Microsoft 365-Konten durch Umgehung von MFA
Mehr: https://maniabel.work/archiv/1660
#Kali365, #Phishing #MFA #Microsoft365 #OAuth-Token #phishing-as-a-service #PhaaS
#up2date #BeDiS

Chinese PhaaS Ecosystem Evolves, Threatens Global Financial Security

The game has changed in the world of phishing: attackers are now using Phishing as a Service (PhaaS) to intercept one-time passcodes and tokenize payment cards, giving them direct control over victims' financial accounts. This sinister shift threatens global financial security, allowing attackers to tap into accountsโ€ฆ

https://osintsights.com/chinese-phaas-ecosystem-evolves-threatens-global-financial-security?utm_source=mastodon&utm_medium=social

#PhishingAsAService #Phaas #FinancialSecurity #GoogleThreatIntelligenceGroup #Gtig

Chinese PhaaS Ecosystem Evolves, Threatens Global Financial Security

Learn how Chinese PhaaS providers evolve to threaten global finance with real-time interception and tokenization, and take action to secure your financial security now.

OSINTSights
Post 3/3
This isn't new technique -- it traces to Russian state actors in mid-2024. What's new is the commodity layer. EvilTokens as a service in February 2026, 340+ organisations compromised within weeks. Kali365 in April. FBI PSA yesterday. The gap between "state-sponsored" and "Telegram subscription" is now measured in months.
Block device code flow in Entra ID Conditional Access. That's it. It was available before Kali365 existed.
https://haunted.lighthouse.co.im/articles/the-mfa-that-wasnt/
#InfoSec #MFA #PhaaS
The MFA That Wasn't

The FBI has warned about Kali365, a Phishing-as-a-Service kit that doesn't steal your password or intercept your MFA code. It steals your OAuth token after you complete authentication yourself. The victim is the MFA step.

FBI warnt vor PhaaS-Plattform Kali365 โ€“ Microsoft-365-Konten im Visier

Das FBI warnt vor Kali365: Die Phishing-Plattform umgeht MFA und stiehlt OAuth-Token aus Microsoft-365-Konten. SchutzmaรŸnahmen im รœberblick.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit

Tycoon2FA-Phishing nutzt 2FA gegen MS365

Seit Ende April 2026 beobachten Sicherheitsexperten eine neue Welle von Phishing-Angriffen, die selbst die Zwei-Faktor-Authentifizierung (MFA) fรผr eigene, kriminelle Zwecke nutzen.

Mehr: https://maniabel.work/archiv/1591

#2FA #Microsoft365 #PhaaS #Phishing #PhishingAsAService #Trustifi