EvilTokens PhaaS scales device code phishing for low-skilled cybercriminals
Threat Actor Meta
Summary
Hide ▲
Show ▼
EvilTokens is turning device code phishing into a phishing-as-a-service market, expanding access for low-skilled cybercriminals and accelerating competition among phishing kits. The shift matters because turnkey services lower the barrier to account takeover and help the technique spread across cloud login flows. Researchers said the kit has become a prominent driver of mainstream adoption, with rival platforms already competing in the same ecosystem. The broader market now includes at least 11 kits using SaaS-themed lures, cloud hosting, and anti-bot protections.
Related Happenings
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
TeamPCP uses Shai-Hulud release to build access-broker monetization pipeline
Threat Actor Meta
H score16
First: 18.05.2026 22:53
Last: 18.05.2026 22:53
Sources 1
About this happening:
TeamPCP is being framed as using the Shai-Hulud source-code release to drive an access broker business, turning worm distribution into a credential-monetization pipeli...
TeamPCP uses Shai-Hulud release to build access-broker monetization pipeline
Threat Actor MetaAbout this happening: TeamPCP is being framed as using the Shai-Hulud source-code release to drive an access broker business, turning worm distribution into a credential-monetization pipeli...
QR code phishing surged across email threats in Q1 2026
Trend
H score73
First: 05.05.2026 09:35
Last: 05.05.2026 09:35
Sources 1
About this happening:
Q1 2026 email-threat telemetry shows QR code phishing and CAPTCHA-gated phishing rising quickly, increasing the risk of credential theft across organizations....
QR code phishing surged across email threats in Q1 2026
TrendAbout this happening: Q1 2026 email-threat telemetry shows QR code phishing and CAPTCHA-gated phishing rising quickly, increasing the risk of credential theft across organizations....
Shifty Corsair evolves open-source supply-chain tradecraft with fake firms, layered packages, and AI-assisted deception
Threat Actor Meta
H score42
First: 29.04.2026 17:43
Last: 29.04.2026 17:43
Sources 1
About this happening:
Shifty Corsair has expanded its operating model into a more convincing developer-lure ecosystem, increasing the risk of open-source supply-chain compromise against Web3 ta...
Shifty Corsair evolves open-source supply-chain tradecraft with fake firms, layered packages, and AI-assisted deception
Threat Actor MetaAbout this happening: Shifty Corsair has expanded its operating model into a more convincing developer-lure ecosystem, increasing the risk of open-source supply-chain compromise against Web3 ta...
Triad Nexus investment scam and brand impersonation campaign targeting emerging markets
Campaign
H score33
First: 14.04.2026 15:00
Last: 14.04.2026 15:00
Sources 1
About this happening:
The Triad Nexus campaign is continuing to run large-scale investment scams and brand impersonation, expanding into emerging markets and driving higher fraud losses...
Triad Nexus investment scam and brand impersonation campaign targeting emerging markets
CampaignAbout this happening: The Triad Nexus campaign is continuing to run large-scale investment scams and brand impersonation, expanding into emerging markets and driving higher fraud losses...
Timeline
-
04.04.2026 17:17 2 articles · 3mo ago
EvilTokens drives device code phishing market growth
Technical Analysis UpdateSekoia and Push Security characterize EvilTokens as a phishing-as-a-service operation that is helping turn device code phishing into a scalable account-takeover market, with Push Security reporting a 37.5x increase in detected pages and at least 11 phishing kits using SaaS-themed lures, anti-bot protections, and cloud-hosted infrastructure.
Show sources
- Device code phishing attacks surge 37x as new kits spread online — www.bleepingcomputer.com — 04.04.2026 17:17
- Device code phishing attacks surge 37x as new kits spread online — www.bleepingcomputer.com — 04.04.2026 17:17