If you've ever signed up for a streaming service, you already understand the business model behind today's most dangerous phishing attacks. Cybercriminals have built a subscription economy around account compromise and just like that streaming service, they offer tiered pricing, feature updates, and customer support. The difference is what they deliver, the keys to your organization.
This is Phishing as a Service, or PhaaS. And it's worth understanding, because the threat it presents isn't abstract. It's operational, it's affordable, and it's being used right now against organizations just like yours.
Early phishing was an art. Attackers hand-crafted fake login pages, bought bulk email lists, and manually worked through every step of a campaign. It was time-consuming, required real technical skill, and had a relatively low success rate. If your organization had decent email filtering and reasonably alert employees, you had a fighting chance.
PhaaS platforms are turnkey attack services that can be rented by the month, managed through dashboards, and capable of executing sophisticated campaigns with minimal human effort. We're not talking about a sketchy tool on a shady darkweb forum. We're talking about polished platforms with documentation, onboarding, and MFA bypass built right in.
That last point is key. Multi-factor authentication was supposed to be the great equalizer. Even if an attacker stole your password, they still needed your phone. Modern PhaaS kits have largely solved that problem, using a technique called Adversary-in-the-Middle (AiTM) that intercepts your active login session and steals the authentication token your browser gets after you successfully verify. Your password and your MFA code are both captured, in real time, without you knowing.
Here's the part that brings this home: these aren't expensive black-market rarities. They're priced like SaaS tools.
|
Kit |
First Seen |
Pricing |
Core Capabilities |
|
EvilTokens |
Feb 2026 |
$600–$1,500 + $500/mo |
OAuth device code phishing; M365 token harvest; automated BEC workflow; LLM-powered email drafting and mailbox mining |
|
Tycoon 2FA |
Aug 2023 |
$350/mo |
AiTM reverse proxy; M365 & Google MFA bypass; session cookie theft; dynamic brand impersonation; rotating infrastructure |
|
EvilProxy |
May 2022 |
$400-$600/mo |
Multi-platform AiTM (Microsoft, Google, 100+ services); session cookie theft; one-click Docker deployment; 1M+ attacks/month at peak |
|
Sneaky 2FA |
Oct 2024 |
Approx. $200/mo |
M365 AiTM; email pre-fill; browser-in-browser (BitB) technique; anti-bot Cloudflare Turnstile; bot-driven Telegram delivery |
|
Mamba 2FA |
Nov 2023 |
$250/mo |
Multi-target AiTM; M365 & Google MFA bypass; live session hijacking; rotating URLs; OneDrive/SharePoint brand impersonation |
|
Rockstar 2FA |
May 2024 |
$350/mo |
AiTM; 50+ login page themes; FUD link rotation; Telegram bot integration; 5,000+ phishing domains linked |
|
Greatness |
July 2022 |
Approx. $120/mo |
M365-specialized AiTM; auto-branded login clones; user email pre-population; HTML attachment generator; Telegram cookie delivery |
For a few hundred dollars a month, a threat actor with no deep technical background can run a campaign that bypasses your MFA, harvests your employees' session tokens, and compromises accounts before your security team has finished their morning coffee. The newest kits now incorporate artificial intelligence as well, large language models that can analyze a compromised mailbox, identify high-value email threads about payments or invoices, and draft convincing follow-on fraud emails automatically. The attacker becomes an operator pushing buttons, not a craftsman exercising skill.
The old mental model of a phishing attack involved a suspicious email, an alert employee, and a help desk ticket. That model fails against modern PhaaS for a few reasons.
The good news is that the controls that stop PhaaS attacks are known. The bad news is that many organizations haven't fully deployed them.
The barrier to running a sophisticated phishing campaign is lower than it has ever been. PhaaS has turned account compromise into a service economy where the product is access to your organization, the pricing is accessible, and the customer support is real. Law enforcement takedowns help but new platforms consistently fill the gap, often with improved capabilities.
Your organization's defensive posture and training needs to be calibrated to this reality. Not to the phishing attacks of five years ago, but to a market where a motivated attacker can provision a fully automated, MFA-bypassing, AI-assisted attack platform for slightly more than the cost of a monthly gym membership. The subscription model works both ways, the question is whether your defenses are keeping up.
+1 833.473.2759 (+1 833.4SecSky)