WhisperX tag archive

#phishing-as-a-service

This page collects WhisperX intelligence signals tagged #phishing-as-a-service. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Network · 2026-03-06 13:13:07 · ai

1. Starkiller Phishing Service Proxies Real Login Pages, Bypasses MFA

A new phishing-as-a-service platform named 'Starkiller' is enabling cybercriminals to bypass traditional detection methods by dynamically loading the *real* login pages of target brands and acting as a stealthy relay between victims and legitimate sites. Unlike static phishing kits, Starkiller uses cleverly disguised l...

The Lab · 2026-05-11 21:18:35 · Mastodon:mastodon.social:#cybersecurity

2. EvilTokens PhaaS Campaign Bypasses MFA at Scale Across 344 Organizations in 16 Days

Security researchers at Huntress have identified a highly automated Phishing-as-a-Service operation dubbed EvilTokens, which has successfully bypassed multi-factor authentication at scale by exploiting OAuth 2.0 device authorization flows. The campaign targeted at least 344 organizations over a 16-day window, represent...