July 2026 saw coordinated phishing and malware campaigns targeting US, European, and Brazilian organizations through abuse of trusted business platforms and legitimate authentication flows. Key threats include Kratos and Kali365 phishing-as-a-service operations targeting Microsoft 365 accounts via credential theft and device code phishing, multiple stealer/RAT families (DestinyStealer, DARTHVADER, Banana RAT, OVERLORD RAT) collecting broad credential and session data, and PhantomEnigma's abuse of compromised Brazilian government infrastructure for malware delivery. Attackers consistently used legitimate tools and rotating infrastructure to evade indicator-based defenses.
Phishing-as-a-Service
7 posts
Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers Email threat landscape: Q2 2026 trends and insights Microsoft's Q2 2026 email threat report details the sustained downstream impact of the Tycoon2FA PhaaS disruption (92% volume decline) alongside a broader shift toward alternative delivery mechanisms including QR codes, CAPTCHA-gated pages, and increasingly Microsoft Teams-based vishing. Two notable campaigns illustrate operational sophistication: a fully automated, API-driven BEC operation reaching tens of thousands of victims in hours, and a multi-stage credential-phishing-to-malware chain abusing Microsoft's OAuth silent sign-in flow and a legitimate ClickUp attachment host to deliver a PowerShell-based BAT dropper.
AI Security Report 2026 The Check Point Research AI Security Report 2026 highlights the transition of AI from an attack assistant to a live attack operator. Threat actors are now using AI to build deployment-ready malware, run live intrusions, and scale social engineering attacks using forged virtual identities. The report also notes a significant rise in indirect prompt injection attacks and persistent enterprise data leakage through GenAI applications.
25th May – Threat Intelligence Report This threat intelligence report highlights multiple high-profile breaches, including 7-Eleven and GitHub, alongside the active exploitation of vulnerabilities in Windows Defender, Trend Micro, and Drupal. It also details emerging threats such as the Kali365 phishing kit, AI-driven prompt injection attacks, the Nimbus Manticore IRGC-linked campaign deploying the MiniFast backdoor, and a supply chain attack on Laravel Lang packages.
2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services Chinese-language Phishing-as-a-Service (PhaaS) platforms are evolving to utilize real-time interception and AI-driven automation to bypass MFA and tokenize stolen payment data into digital wallets. Threat actors leverage encrypted messaging protocols like RCS and iMessage for delivery, while platforms like YY Lai Yu provide highly localized, dynamic phishing infrastructure to target global consumers.
Email threat landscape: Q1 2026 trends and insights In Q1 2026, Microsoft observed 8.3 billion email-based phishing threats, characterized by a 146% surge in QR code phishing and rapid evolution in CAPTCHA-gated payload delivery. Despite disruption efforts against the Tycoon2FA adversary-in-the-middle (AiTM) platform, threat actors quickly adapted their infrastructure, while Business Email Compromise (BEC) remained highly prevalent using conversational social engineering.
Meet Bluekit: The AI-Powered All-in-One Phishing Kit Varonis Threat Labs analyzed Bluekit, a comprehensive Phishing-as-a-Service platform that consolidates domain management, site creation, credential harvesting, and session token theft into a single dashboard. Notably, the kit integrates an AI Assistant powered by uncensored LLMs to draft phishing lures and features advanced post-login session hijacking capabilities, including automated cookie dumping and live target monitoring to bypass standard MFA controls.