ANY.RUN analysis of 16K+ organizations reveals that 72.7% of finance sector investigations involve phishing, with five major phishing kits (Tycoon2FA, Sneaky2FA, EvilProxy, ClickFix, EvilTokens) accounting for the majority of threats. Attackers increasingly abuse legitimate services and employ session hijacking techniques that bypass traditional MFA. A fake Microsoft authentication page hosted on aditipoddar.org was identified as an example of adversary-in-the-middle phishing infrastructure.
BEC
18 posts
US Finance Under Phishing Pressure: What the SOC Data Reveals? What Good Identity Hardening Looks Like Attackers are shifting from network perimeter breaches to identity compromise, leveraging stolen credentials and session tokens to access consolidated SSO environments. MFA alone is insufficient; gaps like overprivileged accounts, unmonitored session tokens, and MFA exceptions create exploitable paths. The article describes ClickFix social engineering and a real-world BEC case to illustrate the impact of identity security gaps.
Describing attacks with crime script analysis The article introduces crime script analysis (CSA) as a narrative-driven technique for describing cyber attacks alongside or as an alternative to TTP-based frameworks like MITRE ATT&CK. Using a business email compromise (BEC) case study, the author demonstrates how AI can industrialize BEC attacks by automating reconnaissance and social engineering message generation. The article identifies specific intervention points across the seven-step BEC crime script where defenders can disrupt attacker workflows.
Payroll Pirates: Strange New Tides in Business Email Compromise Arctic Wolf Labs is tracking an active adversary-in-the-middle (AiTM) phishing campaign compromising Microsoft 365 accounts across multiple sectors and regions. The campaign uses voicemail-themed phishing emails with multi-stage redirect chains through legitimate services (Google Meet, Google Ads, AWS S3) to reach AiTM proxy domains that relay Microsoft authentication and intercept session tokens even when MFA is enabled. Stolen sessions are maintained via automated 8-hour sign-in cadences from rotating residential proxies, followed by Microsoft Graph reconnaissance of payroll/HR/finance personnel and coordinated mailbox collection. The campaign shares characteristics with Microsoft's Storm-2755 (Payroll Pirates) cluster and avoids traditional BEC behaviors to evade detection.
Email threat landscape: Q2 2026 trends and insights Microsoft's Q2 2026 email threat report details the sustained downstream impact of the Tycoon2FA PhaaS disruption (92% volume decline) alongside a broader shift toward alternative delivery mechanisms including QR codes, CAPTCHA-gated pages, and increasingly Microsoft Teams-based vishing. Two notable campaigns illustrate operational sophistication: a fully automated, API-driven BEC operation reaching tens of thousands of victims in hours, and a multi-stage credential-phishing-to-malware chain abusing Microsoft's OAuth silent sign-in flow and a legitimate ClickUp attachment host to deliver a PowerShell-based BAT dropper.
LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses LevelBlue's Q2 2026 TTP Briefing highlights that identity-based attacks—compromised credentials, OAuth tokens, API keys, and machine identities—are outpacing traditional perimeter and MFA defenses, with BEC (45% of incidents) achieving 100% MFA bypass and cloud/supply chain intrusions rising sharply via abused third-party integrations (e.g., the Klue/Salesforce compromise). Phishing remains the top initial access vector (65%), edge/VPN appliance CVEs continue to be heavily exploited for credentialless access, and overall dwell time is shrinking as attackers compress the intrusion path from initial access to impact.
5 Key Takeaways from the Cofense 2026 Mid-Year Threat Report Webinar The Cofense 2026 Mid-Year Threat Report highlights how generative AI is transforming the phishing landscape by enabling polymorphic campaigns, highly convincing business email compromise (BEC), and the weaponization of legitimate remote access tools. The report emphasizes that traditional, indicator-based email defenses are no longer sufficient and advocates for a campaign-level defense approach that correlates behavioral patterns and infrastructure to stop modern threats.
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. A financially motivated fraud ring tracked by CYBERA under the name 'Diligent Planner' is impersonating US city and county planning departments to collect fake permit fees from property owners with active applications. The scheme exploits the fact that customer-authorized payments bypass behavioral fraud controls, making beneficiary mule accounts the primary detectable signal. The operation uses disposable webmail identities, US-based mule accounts operated by foreign actors, and is shifting toward instant P2P rails and smaller regional banks.
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos identified ARToken, a phishing-as-a-service platform linked to EvilTokens, that abuses Microsoft's OAuth 2.0 Device Authorization Grant to bypass MFA and capture victim tokens. The platform provides affiliates with a comprehensive post-compromise toolkit including PRT-based persistence surviving password resets, BEC email operations, inbox rule manipulation, and SharePoint exfiltration. ARToken deploys a sophisticated seven-layer client-side anti-analysis system and abuses legitimate sharepoint.com URLs from attacker-controlled Microsoft 365 workspaces to evade security scanners.
“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security Attackers are weaponizing Amazon Simple Email Service (SES) using compromised AWS IAM keys to launch highly convincing phishing and Business Email Compromise (BEC) campaigns. Because the emails originate from legitimate Amazon infrastructure, they successfully pass standard authentication protocols like SPF, DKIM, and DMARC, making detection difficult without disrupting legitimate business workflows.
Email threat landscape: Q1 2026 trends and insights In Q1 2026, Microsoft observed 8.3 billion email-based phishing threats, characterized by a 146% surge in QR code phishing and rapid evolution in CAPTCHA-gated payload delivery. Despite disruption efforts against the Tycoon2FA adversary-in-the-middle (AiTM) platform, threat actors quickly adapted their infrastructure, while Business Email Compromise (BEC) remained highly prevalent using conversational social engineering.
Your Security Program Was Built for a Threat Landscape That No Longer Exists A recent Huntress survey reveals that modern security teams struggle primarily with alert fatigue and a shifting threat landscape rather than budget constraints. Organizations are increasingly vulnerable to identity-based attacks such as business email compromise and session hijacking, necessitating a strategic pivot from traditional endpoint-centric prevention to Identity Threat Detection and Response (ITDR) supported by AI.
EvilTokens: an AI-augmented Phishing-as-a-Service for automating BEC fraud – Part 2 EvilTokens is an advanced Phishing-as-a-Service (PhaaS) platform that automates Business Email Compromise (BEC) attacks via Microsoft device code phishing. It uniquely integrates AI models to automatically analyze compromised mailboxes, identify financial targets, and generate context-aware BEC lures, significantly reducing the time and skill required for threat actors to monetize compromised accounts.
Intelligence Center Advancements in AI have democratized Business Email Compromise (BEC) attacks, allowing threat actors to efficiently target smaller organizations with tailored social engineering. Concurrently, attackers are exploiting the React2Shell vulnerability (CVE-2025-55182) in Next.js applications to harvest cloud and database credentials, while Qilin ransomware has been observed deploying a sophisticated EDR-killing payload.
New widespread EvilTokens kit: device code phishing as-a-service – Part 1 EvilTokens is a newly discovered Phishing-as-a-Service (PhaaS) platform that automates Microsoft device code phishing to facilitate Business Email Compromise (BEC). By tricking victims into authorizing a malicious device via legitimate Microsoft login portals, attackers harvest access and refresh tokens to gain persistent, unauthenticated access to Microsoft 365 environments.
Huntress Managed ITDR for Google Workspace: Defending the New Identity Attack Surface Threat actors are increasingly targeting Google Workspace as a foundational identity layer to pivot into interconnected SaaS applications. Modern attacks bypass traditional endpoint defenses by utilizing stolen credentials, OAuth abuse, and malicious inbox rules to conduct Business Email Compromise (BEC) and maintain persistent access.
Tycoon2FA Phishing-as-a-Service Platform Persists Following Takedown Following a major law enforcement takedown of its infrastructure on March 4, 2026, the Tycoon2FA Phishing-as-a-Service (PhaaS) platform has quickly reconstituted its operations. The platform continues to enable cybercriminals to bypass multifactor authentication (MFA) using Adversary-in-the-Middle (AiTM) techniques, leading to cloud account takeovers and Business Email Compromise (BEC).
TrendAI™ Supports Global Law Enforcement Efforts Trend Micro collaborated with INTERPOL and other global law enforcement agencies in Operation Synergia III, leading to the takedown of 45,000 malicious servers and 94 arrests. The operation targeted distributed infrastructure supporting widespread cybercrime, including BEC, phishing, and extortion schemes.