PhaaS is a tool tracked across 6 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 11, 2025; most recent activity June 17, 2026.
SpyCloud's 2026 Phishing Pulse Report reveals a significant rise in phishing attacks, with 86% of Fortune 100 companies experiencing employee data exposure. The report indicates that 78% of organizations noted an…
The Sneaky2FA phishing-as-a-service kit has integrated Browser-in-the-Browser (BITB) techniques to enhance its ability to steal Microsoft 365 credentials. This updated functionality allows attackers to create deceptive…
The Sneaky2FA phishing-as-a-service kit has been upgraded to include Browser-in-the-Browser (BITB) techniques, allowing attackers to create deceptive phishing pages that mimic legitimate login interfaces. This evolution…
The Starkiller phishing kit has been identified as a new tool that allows cybercriminals to spoof real login pages and bypass multi-factor authentication (MFA). This commercial-grade platform, detailed by researchers at…
The Quantum Route Redirect phishing-as-a-service platform is exploiting nearly 1,000 domains to steal Microsoft 365 user credentials. Discovered by KnowBe4 in August 2025, this platform automates phishing attacks,…
A new phishing automation platform called Quantum Route Redirect has been identified, targeting Microsoft 365 users worldwide. This tool simplifies credential theft by automating the phishing process, utilizing around…