SecureSky Insights | Cloud Security Blog

Cybercrime Has a Subscription Plan and It Is Targeting You

Written by Jonah Delzell | Aug 24, 2026

If you've ever signed up for a streaming service, you already understand the business model behind today's most dangerous phishing attacks. Cybercriminals have built a subscription economy around account compromise and just like that streaming service, they offer tiered pricing, feature updates, and customer support. The difference is what they deliver, the keys to your organization.

This is Phishing as a Service, or PhaaS. And it's worth understanding, because the threat it presents isn't abstract. It's operational, it's affordable, and it's being used right now against organizations just like yours.

Early phishing was an art. Attackers hand-crafted fake login pages, bought bulk email lists, and manually worked through every step of a campaign. It was time-consuming, required real technical skill, and had a relatively low success rate. If your organization had decent email filtering and reasonably alert employees, you had a fighting chance.

PhaaS platforms are turnkey attack services that can be rented by the month, managed through dashboards, and capable of executing sophisticated campaigns with minimal human effort. We're not talking about a sketchy tool on a shady darkweb forum. We're talking about polished platforms with documentation, onboarding, and MFA bypass built right in.

That last point is key. Multi-factor authentication was supposed to be the great equalizer. Even if an attacker stole your password, they still needed your phone. Modern PhaaS kits have largely solved that problem, using a technique called Adversary-in-the-Middle (AiTM) that intercepts your active login session and steals the authentication token your browser gets after you successfully verify. Your password and your MFA code are both captured, in real time, without you knowing.

Here's the part that brings this home: these aren't expensive black-market rarities. They're priced like SaaS tools.

Kit

First Seen

Pricing

Core Capabilities

EvilTokens

Feb 2026

$600–$1,500 + $500/mo

OAuth device code phishing; M365 token harvest; automated BEC workflow; LLM-powered email drafting and mailbox mining

Tycoon 2FA

Aug 2023

$350/mo

AiTM reverse proxy; M365 & Google MFA bypass; session cookie theft; dynamic brand impersonation; rotating infrastructure

EvilProxy

May 2022

$400-$600/mo

Multi-platform AiTM (Microsoft, Google, 100+ services); session cookie theft; one-click Docker deployment; 1M+ attacks/month at peak

Sneaky 2FA

Oct 2024

Approx. $200/mo

M365 AiTM; email pre-fill; browser-in-browser (BitB) technique; anti-bot Cloudflare Turnstile; bot-driven Telegram delivery

Mamba 2FA

Nov 2023

$250/mo

Multi-target AiTM; M365 & Google MFA bypass; live session hijacking; rotating URLs; OneDrive/SharePoint brand impersonation

Rockstar 2FA

May 2024

$350/mo

AiTM; 50+ login page themes; FUD link rotation; Telegram bot integration; 5,000+ phishing domains linked

Greatness

July 2022

Approx. $120/mo

M365-specialized AiTM; auto-branded login clones; user email pre-population; HTML attachment generator; Telegram cookie delivery

For a few hundred dollars a month, a threat actor with no deep technical background can run a campaign that bypasses your MFA, harvests your employees' session tokens, and compromises accounts before your security team has finished their morning coffee. The newest kits now incorporate artificial intelligence as well, large language models that can analyze a compromised mailbox, identify high-value email threads about payments or invoices, and draft convincing follow-on fraud emails automatically. The attacker becomes an operator pushing buttons, not a craftsman exercising skill.

The old mental model of a phishing attack involved a suspicious email, an alert employee, and a help desk ticket. That model fails against modern PhaaS for a few reasons.

  • AI-generated phishing content doesn't have the grammatical tells and awkward phrasing that trained employees learn to spot. The emails are fluent, contextually appropriate, and increasingly personalized. Your finance team might get an email that references your actual CFO's communication style. Your IT staff might see a message that knows which software your organization uses.

  • PhaaS campaigns use legitimate and distributed cloud services as redirect layers, rotate through dozens of domains, and filter out security researchers before showing the real phishing page. Traditional blocklists struggle to keep up.

  • Once a kit captures credentials or a session token, automated modules immediately pivot to reconnaissance, data harvesting, and fraud execution. There's no "slow burn" where your team has time to notice something's wrong. The attack completes in minutes.

The good news is that the controls that stop PhaaS attacks are known. The bad news is that many organizations haven't fully deployed them.

  • The AiTM bypass built into every modern PhaaS kit means that SMS-based or app-based MFA can be circumvented if a session token is stolen. Phishing-resistant MFA, specifically FIDO2/passkey-based authentication, is the standard that holds up against these techniques. If your critical applications aren't there yet, it's worth prioritizing.

  • PhaaS kits are specifically engineered to find and exploit gaps around geographic exclusions, trusted networks that are too broadly defined, policies that don't cover certain device types or authentication paths. Every exception in your policy is a potential attack vector.

  • If your identity-based alert rules run on schedules, you have attacker dwell time baked in as an acceptable outcome. Authentication anomalies need near-real-time detection to matter.

The barrier to running a sophisticated phishing campaign is lower than it has ever been. PhaaS has turned account compromise into a service economy where the product is access to your organization, the pricing is accessible, and the customer support is real. Law enforcement takedowns help but new platforms consistently fill the gap, often with improved capabilities.

Your organization's defensive posture and training needs to be calibrated to this reality. Not to the phishing attacks of five years ago, but to a market where a motivated attacker can provision a fully automated, MFA-bypassing, AI-assisted attack platform for slightly more than the cost of a monthly gym membership. The subscription model works both ways, the question is whether your defenses are keeping up.

For more information about SecureSky, or assistance with combatting  AI-based attacks, please contact us at:

https://securesky.com/contact-us/

info@securesky.com

+1 833.473.2759  (+1 833.4SecSky)