<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Phishing-as-a-Service on CuraSec</title><link>https://curasec.metacog.co.kr/tags/phishing-as-a-service/</link><description>Recent content in Phishing-as-a-Service on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 26 Aug 2026 11:42:13 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/phishing-as-a-service/index.xml" rel="self" type="application/rss+xml"/><item><title>AnonyMousKIT PhaaS uses voice AI to phish stolen iPhone passcodes</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-pass/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-pass/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The use of automated voice AI agents in a PhaaS platform to socially engineer victims is a meaningful escalation in vishing sophistication; no IOCs or enterprise detection surface are available yet, but analysts should track how this technique migrates toward corporate credential theft campaigns.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Mirage2FA PhaaS Bypasses M365 MFA, 4,500 US/EU Firms Targeted</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-mirage2fa-surge-hits-4-500-us-and-eu-companies-abusing-micro/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-mirage2fa-surge-hits-4-500-us-and-eu-companies-abusing-micro/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> AiTM phishing that defeats standard MFA is a config problem, not a patch problem — audit your Entra ID Conditional Access policies and prioritize migrating M365 users to phishing-resistant MFA (FIDO2/passkeys) this quarter, as TOTP and SMS are insufficient against this class of attack.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> This campaign is active and broadly targeting US enterprises via M365; hunt for AiTM indicators in Entra ID sign-in logs now — flag token issuance from unexpected IPs, session establishment followed by unusual API activity, and impossible-travel events from the same session cookie.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> With 4,500 organizations targeted and ~48% of targeted addresses potentially compromised, confirm with your team this week that phishing-resistant MFA is enforced for M365 and assess whether your domain appeared in ANY.RUN&amp;rsquo;s targeting data; this is board-question territory given the scale.&lt;/li>
&lt;/ul></description></item><item><title>Greatness PhaaS Adds Device Code Phishing to Bypass MFA</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Device code flow abuse bypasses MFA by design; audit your identity provider (Entra ID, Okta) and restrict or disable the OAuth Device Authorization Grant for users/apps that don&amp;rsquo;t require it — block or conditional-policy-gate this flow this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs provided, but Greatness PhaaS commoditizing device code phishing signals growing campaign volume; build detections in Entra/Okta logs for unexpected device code authorization requests, particularly outside normal device-enrollment windows.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> MFA bypass techniques are now packaged in commercial crimeware toolkits, eroding the assurance value of standard MFA — useful context for risk register updates and for evaluating phishing-resistant auth (FIDO2/passkeys) as a strategic control.&lt;/li>
&lt;/ul></description></item><item><title>Greatness PhaaS expands to AiTM and device-code attacks on M365</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-phishing-service-spoofs-ringcentral-to-steal-microsoft-365-a/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-phishing-service-spoofs-ringcentral-to-steal-microsoft-365-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> AiTM and device-code phishing bypass standard MFA; audit your M365 conditional access policies to restrict or block device code flow, and prioritize phishing-resistant MFA (FIDO2 or certificate-based) for privileged accounts this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for suspicious device-code OAuth grant flows and anomalous session token reuse in Entra ID / M365 audit logs — the AiTM component means valid MFA completion is not a reliable innocence signal.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Confirms that commodity phishing platforms are now routing around standard MFA at scale; useful background when justifying a phishing-resistant MFA upgrade on the roadmap or fielding customer security questionnaires about M365 identity controls.&lt;/li>
&lt;/ul></description></item><item><title>Police dismantle Kratos phishing platform, arrest developer</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-police-dismantle-kratos-phishing-platform-arrest-developer/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-police-dismantle-kratos-phishing-platform-arrest-developer/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The Kratos PhaaS takedown removes active infrastructure but no IOCs or TTPs are published in this item, so there is no immediate detection or hunt to run; useful background on the phishing-as-a-service ecosystem.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A major PhaaS platform serving global customers has been dismantled — useful context for threat landscape briefings, but no immediate vendor exposure or regulatory action is required.&lt;/li>
&lt;/ul></description></item></channel></rss>