Three distinct Phishing-as-a-Service (PhaaS) platforms—Sneaky 2FA, EvilTokens, and EvilProxy—are actively targeting US organizations to steal Microsoft 365 credentials and session tokens, effectively neutralizing standard multi-factor authentication (MFA) protections This article explores phishing service phaas. .

Attack Techniques - AiTM Reverse-relay phishing page - OAuth 2.0 Device Code Grant abuse First Observed: October 2024 (Sekoia, Dec 2024) Mid-February 2026 | May 2022 Operators/Brands: - "Sneaky Log" Telegram PhaaS - EvilTokens PhaaS platform - EvilProxy dark-web PhaaS Credential Theft Method - Relays creds live to Microsoft API, captures session cookie - Victim authorizes attacker’s OAuth client; only tokens stolen - Reverse proxy relays creds + cookies in real time MFA Interaction - Victim completes real MFA; cookie skimmed post-auth - Victim completes real MFA; token issued directly to attacker - Victim completes real MFA; cookie/token intercepted mid-flight Primary Evasion Techniques - Cloudflare Turnstile/reCAPTCHA, IP/data-center filtering, Wikipedia redirects for bots - Multi-redirect chains via trusted sites, bot-protection walls, AI-generated lure infrastructure - VM/browser fingerprinting, random URLs, near-identical clone of real login page Pricing (underground) - ~$200/month subscription - Not publicly priced; sold as "complete BEC operations environment" - Sold as PhaaS on dark web marketplaces since 2022 Scale Observed: - ~100 domains tracked by early Jan 2025; 61+ IOCs documented - 340+ M365 organizations compromised across 7+ countries since Feb 2026 - 100+ organizations, executives/managers targeted in a single 2023 wave The leaked source code reveals that it reuses components from the W3LL OV6 AiTM kit reported by Group-IB in 2023, including identical User-Agent handling logic and cookie-parsing functions.