---
title: Cybercrime Has a Subscription Plan and It Is Targeting You
description: Cybercrime now runs like SaaS, with PhaaS kits that bypass MFA for a few hundred dollars a month. Here's how it works and how to defend your organization.
image: https://blog.securesky.com/hubfs/Image2.png
---

[![SecureSky](https://blog.securesky.com/hs-fs/hubfs/raw_assets/public/Securesky_March2022/images/SecureSkyLogo-01.png?width=500&height=500&name=SecureSkyLogo-01.png "SecureSky")](https://securesky.com/)

- [What We Do](https://securesky.com/security-services/) 
    - Assessment and Deployment Services 
          - [Cloud Security Assessment](https://securesky.com/security-services/cloud-security-assessment/)
          - [Application Security Assessment](https://securesky.com/security-services/application-security-architecture/)
          - [Penetration Testing](https://securesky.com/security-services/penetration-testing/)
          - [Application Architecture Services](https://securesky.com/security-services/application-architecture-services/)
          - [Microsoft Security (XDR) Deployment](https://securesky.com/security-services/microsoft-security-deployment/)
          - [Microsoft Sentinel (SIEM) Deployment](https://securesky.com/security-services/microsoft-sentinel/)
    - Security Posture Management (CSPM/SSPM) 
          - [Active Protection Platform Overview](https://securesky.com/cloud-security-posture-management/)
          - [Active Protection Platform Technology](https://securesky.com/security-services/active-protection-platform-technology/)
    - Managed XDR Services 
          - [Managed XDR Services Overview](https://securesky.com/security-services/microsoft-sentinel/#XDR)
          - [BEC/ATO Incident Response](https://securesky.com/security-services/business-email-compromise-response/)
- [About Us](https://securesky.com/about-us/) 
    - [Why SecureSky](https://securesky.com/about-us/)
    - [Leadership](https://securesky.com/leadership/)
    - [Careers](https://securesky.com/careers/)
    - [Partners](https://securesky.com/about-us/partners/)
- [Resources](https://securesky.com/resources/) 
    - [Recent News](https://securesky.com/securesky-news/)
    - [Datasheets](https://securesky.com/resources/datasheets/)
    - [eBooks](https://securesky.com/resources/ebooks/)
- [Blog](https://blog.securesky.com)
- [Contact Us](https://securesky.com/contact-us/)
- [Log In](https://portal.securesky.com/login)

- [What We Do](https://securesky.com/security-services/) 
    - Assessment and Deployment Services 
          - [Cloud Security Assessment](https://securesky.com/security-services/cloud-security-assessment/)
          - [Application Security Assessment](https://securesky.com/security-services/application-security-architecture/)
          - [Penetration Testing](https://securesky.com/security-services/penetration-testing/)
          - [Application Architecture Services](https://securesky.com/security-services/application-architecture-services/)
          - [Microsoft Security (XDR) Deployment](https://securesky.com/security-services/microsoft-security-deployment/)
          - [Microsoft Sentinel (SIEM) Deployment](https://securesky.com/security-services/microsoft-sentinel/)
    - Security Posture Management (CSPM/SSPM) 
          - [Active Protection Platform Overview](https://securesky.com/cloud-security-posture-management/)
          - [Active Protection Platform Technology](https://securesky.com/security-services/active-protection-platform-technology/)
    - Managed XDR Services 
          - [Managed XDR Services Overview](https://securesky.com/security-services/microsoft-sentinel/#XDR)
          - [BEC/ATO Incident Response](https://securesky.com/security-services/business-email-compromise-response/)
- [About Us](https://securesky.com/about-us/) 
    - [Why SecureSky](https://securesky.com/about-us/)
    - [Leadership](https://securesky.com/leadership/)
    - [Careers](https://securesky.com/careers/)
    - [Partners](https://securesky.com/about-us/partners/)
- [Resources](https://securesky.com/resources/) 
    - [Recent News](https://securesky.com/securesky-news/)
    - [Datasheets](https://securesky.com/resources/datasheets/)
    - [eBooks](https://securesky.com/resources/ebooks/)
- [Blog](https://blog.securesky.com)
- [Contact Us](https://securesky.com/contact-us/)
- [Log In](https://portal.securesky.com/login)

## SecureSky Insights

# Cybercrime Has a Subscription Plan and It Is Targeting You

Aug 24, 2026 | [Industry Insight](https://blog.securesky.com/tag/industry-insight)

If you've ever signed up for a streaming service, you already understand the business model behind today's most dangerous phishing attacks. Cybercriminals have built a subscription economy around account compromise and just like that streaming service, they offer tiered pricing, feature updates, and customer support. The difference is what they deliver, the keys to your organization.

This is Phishing as a Service, or PhaaS. And it's worth understanding, because the threat it presents isn't abstract. It's operational, it's affordable, and it's being used right now against organizations just like yours.

Early phishing was an art. Attackers hand-crafted fake login pages, bought bulk email lists, and manually worked through every step of a campaign. It was time-consuming, required real technical skill, and had a relatively low success rate. If your organization had decent email filtering and reasonably alert employees, you had a fighting chance.

PhaaS platforms are turnkey attack services that can be rented by the month, managed through dashboards, and capable of executing sophisticated campaigns with minimal human effort. We're not talking about a sketchy tool on a shady darkweb forum. We're talking about polished platforms with documentation, onboarding, and MFA bypass built right in.

That last point is key. Multi-factor authentication was supposed to be the great equalizer. Even if an attacker stole your password, they still needed your phone. Modern PhaaS kits have largely solved that problem, using a technique called Adversary-in-the-Middle (AiTM) that intercepts your active login session and steals the authentication token your browser gets after you successfully verify. Your password and your MFA code are both captured, in real time, without you knowing.

Here's the part that brings this home: these aren't expensive black-market rarities. They're priced like SaaS tools.

| **Kit** | **First Seen** | **Pricing** | **Core Capabilities** |
| --- | --- | --- | --- |
| EvilTokens | Feb 2026 | $600–$1,500 + $500/mo | OAuth device code phishing; M365 token harvest; automated BEC workflow; LLM-powered email drafting and mailbox mining |
| Tycoon 2FA | Aug 2023 | $350/mo | AiTM reverse proxy; M365 & Google MFA bypass; session cookie theft; dynamic brand impersonation; rotating infrastructure |
| EvilProxy | May 2022 | $400-$600/mo | Multi-platform AiTM (Microsoft, Google, 100+ services); session cookie theft; one-click Docker deployment; 1M+ attacks/month at peak |
| Sneaky 2FA | Oct 2024 | Approx. $200/mo | M365 AiTM; email pre-fill; browser-in-browser (BitB) technique; anti-bot Cloudflare Turnstile; bot-driven Telegram delivery |
| Mamba 2FA | Nov 2023 | $250/mo | Multi-target AiTM; M365 & Google MFA bypass; live session hijacking; rotating URLs; OneDrive/SharePoint brand impersonation |
| Rockstar 2FA | May 2024 | $350/mo | AiTM; 50+ login page themes; FUD link rotation; Telegram bot integration; 5,000+ phishing domains linked |
| Greatness | July 2022 | Approx. $120/mo | M365-specialized AiTM; auto-branded login clones; user email pre-population; HTML attachment generator; Telegram cookie delivery |

For a few hundred dollars a month, a threat actor with no deep technical background can run a campaign that bypasses your MFA, harvests your employees' session tokens, and compromises accounts before your security team has finished their morning coffee. The newest kits now incorporate artificial intelligence as well, large language models that can analyze a compromised mailbox, identify high-value email threads about payments or invoices, and draft convincing follow-on fraud emails automatically. The attacker becomes an operator pushing buttons, not a craftsman exercising skill.

The old mental model of a phishing attack involved a suspicious email, an alert employee, and a help desk ticket. That model fails against modern PhaaS for a few reasons.

- AI-generated phishing content doesn't have the grammatical tells and awkward phrasing that trained employees learn to spot. The emails are fluent, contextually appropriate, and increasingly personalized. Your finance team might get an email that references your actual CFO's communication style. Your IT staff might see a message that knows which software your organization uses.
- PhaaS campaigns use legitimate and distributed cloud services as redirect layers, rotate through dozens of domains, and filter out security researchers before showing the real phishing page. Traditional blocklists struggle to keep up.
- Once a kit captures credentials or a session token, automated modules immediately pivot to reconnaissance, data harvesting, and fraud execution. There's no "slow burn" where your team has time to notice something's wrong. The attack completes in minutes.

The good news is that the controls that stop PhaaS attacks are known. The bad news is that many organizations haven't fully deployed them.

- The AiTM bypass built into every modern PhaaS kit means that SMS-based or app-based MFA can be circumvented if a session token is stolen. Phishing-resistant MFA, specifically FIDO2/passkey-based authentication, is the standard that holds up against these techniques. If your critical applications aren't there yet, it's worth prioritizing.
- PhaaS kits are specifically engineered to find and exploit gaps around geographic exclusions, trusted networks that are too broadly defined, policies that don't cover certain device types or authentication paths. Every exception in your policy is a potential attack vector.
- If your identity-based alert rules run on schedules, you have attacker dwell time baked in as an acceptable outcome. Authentication anomalies need near-real-time detection to matter.

The barrier to running a sophisticated phishing campaign is lower than it has ever been. PhaaS has turned account compromise into a service economy where the product is access to your organization, the pricing is accessible, and the customer support is real. Law enforcement takedowns help but new platforms consistently fill the gap, often with improved capabilities.

Your organization's defensive posture and training needs to be calibrated to this reality. Not to the phishing attacks of five years ago, but to a market where a motivated attacker can provision a fully automated, MFA-bypassing, AI-assisted attack platform for slightly more than the cost of a monthly gym membership. The subscription model works both ways, the question is whether your defenses are keeping up.

## *For more information about [SecureSky](https://securesky.com/), or assistance with combatting  AI-based attacks, please contact us at:*

[https://securesky.com/contact-us/](https://securesky.com/contact-us/)

[info@securesky.com](mailto:info@securesky.com)

+1 833.473.2759  (+1 833.4SecSky)

 

### Frequently Asked Questions 

 

 What is Phishing as a Service (PhaaS)?

Phishing as a Service (PhaaS) is a subscription-based cyberattack model that allows attackers to rent ready-made phishing platforms, automate campaigns, bypass MFA, and steal credentials or session tokens. 

 How does Phishing as a Service bypass MFA?

Modern PhaaS kits commonly use Adversary-in-the-Middle (AiTM) attacks to intercept an active login session and steal authentication tokens after a user successfully completes MFA. 

 Can MFA protect against modern phishing attacks?

Traditional SMS- and app-based MFA can be bypassed through session-token theft. Phishing-resistant authentication, such as FIDO2 security keys and passkeys, provides stronger protection against AiTM attacks. 

 How does AI make phishing attacks more dangerous?

AI can help attackers analyze compromised mailboxes, identify valuable conversations about payments or invoices, and generate convincing follow-up emails that are personalized to the target. 

 How can organizations defend against Phishing as a Service attacks?

Organizations can reduce PhaaS risk by deploying phishing-resistant MFA, monitoring authentication anomalies in near real time, limiting overly broad access policies, and strengthening identity and security controls. 

- [What We Do](https://securesky.com/security-services/) 
    - Assessment and Deployment Services 
          - [Cloud Security Assessment](https://securesky.com/security-services/cloud-security-assessment/)
          - [Application Security Assessment](https://securesky.com/security-services/application-security-architecture/)
          - [Penetration Testing](https://securesky.com/security-services/penetration-testing/)
          - [Application Architecture Services](https://securesky.com/security-services/application-architecture-services/)
          - [Microsoft Security Deployment](https://securesky.com/security-services/microsoft-security-deployment/)
          - [Microsoft Sentinel Deployment](https://securesky.com/security-services/microsoft-sentinel/)
    - Security Posture Management (CSPM/SSPM) 
          - [Active Protection Platform Overview](https://securesky.com/cloud-security-posture-management/)
          - [Active Protection Platform Technology](https://securesky.com/security-services/active-protection-platform-technology/)
    - eXtended Detection and Response (XDR) Services 
          - [eXtended Detection and Response Overview](https://securesky.com/security-services/microsoft-sentinel/)
          - [BEC/ATO Incident Response](https://securesky.com/security-services/business-email-compromise-response/)
- [About Us](https://securesky.com/about-us/) 
    - [Why SecureSky](https://securesky.com/about-us/)
    - [Leadership](https://securesky.com/leadership/)
    - [Careers](https://securesky.com/careers/)
    - [Partners](https://securesky.com/about-us/partners/)
- [Resources](https://securesky.com/resources/) 
    - [Recent News](https://securesky.com/securesky-news/)
    - [Datasheets](https://securesky.com/resources/datasheets/)
    - [eBooks](https://securesky.com/resources/ebooks/)
- [Blog](https://blog.securesky.com)
- [Contact Us](https://securesky.com/contact-us/)
- [Log In](https://portal.securesky.com/login)

©2018-2026 SecureSky, Inc. All rights reserved. SafetyNET, SecureSky, AdaptiveDefender and the SecureSky logo are marks of SecureSky, Inc. SecureSky U.S. Patent Nos. 8,347,391; 8,856,324; 9,021,574; 9,350,707; 9,787,713; 9,888,018; 10,015,239. Additional patents pending. Azure and Office 365 are registered trademarks of Microsoft.

[Privacy Policy](https://securesky.com/privacy-policy/)   [Website Terms of Use](https://securesky.com/website-terms-of-use/)

- <https://x.com/securesky>
- <https://www.linkedin.com/company/securesky>

![](https://px.ads.linkedin.com/collect/?pid=4331593&fmt=gif)

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Phishing as a Service (PhaaS) is a subscription-based cyberattack model that allows attackers to rent ready-made phishing platforms, automate campaigns, bypass MFA, and steal credentials or session tokens."
    },
    "name" : "What is Phishing as a Service (PhaaS)?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Modern PhaaS kits commonly use Adversary-in-the-Middle (AiTM) attacks to intercept an active login session and steal authentication tokens after a user successfully completes MFA."
    },
    "name" : "How does Phishing as a Service bypass MFA?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Traditional SMS- and app-based MFA can be bypassed through session-token theft. Phishing-resistant authentication, such as FIDO2 security keys and passkeys, provides stronger protection against AiTM attacks."
    },
    "name" : "Can MFA protect against modern phishing attacks?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "AI can help attackers analyze compromised mailboxes, identify valuable conversations about payments or invoices, and generate convincing follow-up emails that are personalized to the target."
    },
    "name" : "How does AI make phishing attacks more dangerous?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Organizations can reduce PhaaS risk by deploying phishing-resistant MFA, monitoring authentication anomalies in near real time, limiting overly broad access policies, and strengthening identity and security controls."
    },
    "name" : "How can organizations defend against Phishing as a Service attacks?"
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Organization",
    "name" : "SecureSky"
  },
  "dateModified" : "2026-08-27",
  "datePublished" : "2026-08-24",
  "description" : "Cybercrime now runs like SaaS, with PhaaS kits that bypass MFA for a few hundred dollars a month. Here's how it works and how to defend your organization.",
  "headline" : "Cybercrime Has a Subscription Plan and It Is Targeting You",
  "image" : "https://blog.securesky.com/hubfs/Image2.png",
  "mainEntityOfPage" : {
    "@id" : "https://blog.securesky.com/cybercrime-has-a-subscription-plan-and-it-is-targeting-you",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.securesky.com/hs-fs/hubfs/raw_assets/public/Securesky_March2022/images/SecureSkyLogo-01.png?width=750&height=750&name=SecureSkyLogo-01.png"
    },
    "name" : "SecureSky"
  }
}
```