Find notable cyber news and cases, enriched with sources, timelines, and signals.

Tycoon2FA-Kali365-ARToken alliance reshapes ransomware ecosystem operations

Threat Actor Meta
First reported
Last updated
Happening score
H score 89
1 unique sources, 1 articles

Summary

Hide ▲

Phishing-as-a-service kits have turned device code phishing into a commoditized feature, expanding token theft across multiple criminal platforms and accelerating operator access abuse. Tycoon2FA and Kali365 show the technique moving from a niche method into a packaged capability that paying operators can deploy at scale.

Related Happenings

Jalisco and OmegaLord Microsoft 365 phishing kits

Malware Activity
H score27 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...

Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord

Campaign
H score37 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...

The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster

Threat Actor Meta
H score14 First: 13.07.2026 18:30 Last: 13.07.2026 18:30 Sources 1

About this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...

Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking

Threat Actor Meta
H score36 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

How related: The FBI issued a standalone advisory on Kali365, the first US federal agency PSA about a specific phishing-as-a-service kit.

About this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...

Timeline

  1. 31.07.2026 14:24 2 articles · 1h ago

    Device code phishing becomes a standard PhaaS feature

    Campaign Scope Update

    Device code phishing moved from a niche technique into a standard phishing-as-a-service feature, with Tycoon2FA adding the flow in May, Kali365 bundling AiTM and device code phishing in a single platform, and ARToken shipping PRT persistence, mailbox access, BEC automation, and SharePoint exfiltration as product features for paying operators. By April, Microsoft was reporting 10 to 15 entirely new campaigns every 24 hours, Barracuda counted 7 million attacks in four weeks, and more than 25 distinct device code phishing kits were being tracked in the wild.

    Show sources