| # | Platform | Model | Primary Focus | Status |
|---|---|---|---|---|
| 1 | Tycoon2FA | AiTM PhaaS | Microsoft 365 and Gmail | Disrupted in March 2026; renewed activity observed |
| 2 | EvilProxy | AiTM PhaaS | Cloud identities | Active criminal service |
| 3 | Sneaky 2FA | AiTM PhaaS | Microsoft 365 | Active and evolving |
| 4 | CryptoChameleon | Mobile phishing kit | Crypto, SSO, and password managers | Possible renewed activity in 2025 |
| 5 | Darcula | Smishing PhaaS | Consumer and delivery brands | Active; potentially linked to MEA campaigns |
| 6 | Evilginx | Reverse-proxy framework | Multiple online services | Legitimate framework abused in attacks |
| 7 | EvilTokens | Device-code PhaaS | Microsoft 365 | Active in 2026 |
| 8 | BlueKit | Multi-brand PhaaS | Cloud, crypto, finance, and e-commerce | Actively marketed and developed |
| 9 | YY Lai Yu | Localized PhaaS | Japanese consumer and payment brands | Active; more than 400 templates |
| 10 | Telekopye | Telegram scam toolkit | Marketplaces and accommodation booking | Long-running organized scam ecosystem |
Top 10 Phishing Kits Used by Cybercriminals
Phishing kits have turned credential theft into a scalable service by packaging fake login pages, hosting, traffic filtering, victim management, and technical support into ready-made platforms. Advanced services such as Tycoon2FA, EvilProxy, and Sneaky 2FA can also intercept session cookies and bypass MFA methods that are not phishing-resistant, while platforms such as Darcula and Telekopye focus more heavily on smishing and consumer fraud.
This article examines ten prominent platforms selected for their documented use, technical influence, current relevance, and value to defenders. It is not a strict ranking, and disrupted services are identified accordingly.
What Is a Phishing Kit?
A phishing kit is a packaged set of files or services used to impersonate a trusted organization and collect sensitive information. A basic kit may contain HTML templates and a script that sends stolen credentials to an operator. A PhaaS platform can add hosting, campaign management, anti-bot controls, victim filtering, live notifications, technical support, and automated page cloning.
A kit is not the same as a campaign. The kit supplies the technical machinery; the campaign includes the lure, target selection, domain registration, delivery channel, and follow-on fraud. Malware families delivered through phishing are also distinct from phishing kits, even when they appear in the same attack chain.
The Phishing Kit Landscape at a Glance
Top 10 Phishing Kits and Platforms
1. Tycoon2FA
Status: Core infrastructure disrupted in March 2026, although its techniques and associated activity remain relevant.
Tycoon2FA emerged in 2023 as a major AiTM phishing service targeting Microsoft 365, Gmail, and other cloud accounts. Microsoft reported that its campaigns generated tens of millions of phishing messages and reached more than 500,000 organizations each month.
The platform relayed victims’ credentials and MFA responses to legitimate login services before capturing authenticated session cookies. Its operators used rotating domains, CAPTCHA challenges, browser fingerprinting, traffic filtering, QR codes, malicious attachments, and multistage redirects to evade detection.
![2023 Tycoon PhaaS platform website at tycoongroup[.]ws](https://socradar.io/wp-content/uploads/2026/08/tycoon-phaas-platform-website-2023.jpg.webp)
2023 Tycoon PhaaS platform website at tycoongroup[.]ws
In March 2026, Microsoft, Europol, Cloudflare, and other partners disrupted the service and seized 330 domains supporting its phishing infrastructure. The action significantly reduced its central operations, but its reusable code and AiTM techniques remain a concern.
SOCRadar’s earlier analysis of Tycoon2FA examined how the platform developed into a scalable criminal service capable of bypassing conventional MFA.
Defender focus
- Adopt phishing-resistant authentication such as FIDO2 security keys or passkeys.
- Revoke active sessions and refresh tokens after suspected compromise.
- Monitor suspicious session reuse, inbox rules, and authentication-method changes.
- Inspect QR codes, HTML attachments, and multistage redirect chains.
2. EvilProxy
Status: Established criminal PhaaS platform prominently observed in campaigns targeting cloud accounts.
EvilProxy packages reverse-proxy phishing as a service. A victim sees a convincing copy of a legitimate sign-in page while the platform relays authentication requests to the real provider. This allows the operator to capture passwords, MFA responses, and authenticated session cookies, potentially enabling account takeover even after the victim completes a conventional MFA challenge.
The platform lowers the technical barrier to conducting AiTM attacks against Microsoft 365, Google, and other cloud services. Its phishing pages closely reproduce legitimate login experiences, while randomly generated URLs and multi-stage redirects make campaigns more difficult to identify through static indicators.
Barracuda detected more than one million PhaaS attacks during January and February 2025. In its January observations, Tycoon 2FA accounted for 89% of detected PhaaS incidents, followed by EvilProxy at 8% and Sneaky 2FA at 3%. Although Tycoon 2FA dominated the dataset, EvilProxy remained the second-most-observed platform and stood out for its accessibility to attackers with limited technical experience.

EvilProxy was observed in 8% of PhaaS activity in early 2025. Source.
The findings demonstrate that EvilProxy is not simply a proof-of-concept reverse-proxy tool. It is part of a commercial ecosystem that provides ready-to-use infrastructure for credential harvesting, MFA interception, and cloud account takeover.
Defender focus
- Require managed or compliant devices for access to sensitive cloud applications where feasible.
- Apply risk-based conditional access and step-up authentication for privileged actions.
- Use phishing-resistant authentication such as FIDO2 security keys or properly implemented passkeys.
- Alert on token reuse, unexpected MFA prompts, new inbox rules, OAuth persistence, and abnormal file-sharing activity.
- Investigate unfamiliar or randomly generated URLs that lead to Microsoft, Google, or other cloud login pages.
3. Sneaky 2FA
Status: Active AiTM phishing service, with additional Browser-in-the-Browser capabilities documented in late 2025.
Sneaky 2FA is an AiTM phishing kit focused on Microsoft 365. Sekoia found that its operators distributed licensed and obfuscated copies through the Telegram-based Sneaky Log service. Its attack flow can use CAPTCHA or Cloudflare Turnstile challenges to restrict automated analysis before presenting a fraudulent Microsoft authentication page.
The kit captures credentials and authenticated session cookies, allowing operators to take over accounts protected by MFA methods that are not phishing-resistant. Sekoia also identified source-code similarities with W3LL Panel OV6, demonstrating how criminal developers reuse components across competing services.
In November 2025, researchers documented Browser-in-the-Browser functionality in Sneaky 2FA. This technique presents a simulated browser window and address bar inside the phishing page, making the authentication prompt appear to originate from a legitimate Microsoft domain.
Defender focus
- Treat CAPTCHA and Turnstile challenges as access controls, not signs that a website is legitimate.
- Inspect HTML, SVG, and other attachments that initiate multi-stage redirect chains.
- Use phishing-resistant authentication for high-risk Microsoft 365 accounts.
- Monitor unusual sign-ins followed by rapid mailbox access, inbox-rule creation, or file downloads.
4. CryptoChameleon
Status: Documented since 2024, with possible CryptoChameleon-linked activity reported in October 2025.
CryptoChameleon is a mobile-oriented phishing kit capable of reproducing sign-in pages for cryptocurrency exchanges, single sign-on providers, email services, password managers, and government organizations. Lookout initially identified it through an attack impersonating the US Federal Communications Commission and later connected related infrastructure to pages targeting Binance, Coinbase, Gemini, Kraken, LastPass, Okta, Gmail, iCloud, and other services.
The attack flow can combine email, SMS, and voice phishing. CAPTCHA challenges help restrict automated analysis, while convincing sign-in and account-recovery pages collect credentials, authentication codes, password-reset links, and sometimes identity documents. Lookout found that much of the observed victim activity originated from iOS and Android devices, emphasizing the importance of mobile threat visibility.
In October 2025, LastPass warned customers about a social-engineering campaign it assessed as possibly associated with CryptoChameleon, also tracked as UNC5356. Attackers sent messages falsely claiming that someone had requested emergency access to the recipient’s password vault following a death. Some targets reportedly received follow-up calls from attackers impersonating LastPass employees and directing them to phishing pages.

The “legacy request” email used in the possible CryptoChameleon-linked campaign. Source.
LastPass also identified passkey-themed domains, including mypasskey[.]info and passkeysetup[.]com. The campaign illustrates how CryptoChameleon-style operations can combine emotionally persuasive account-recovery stories, voice impersonation, and brand-specific phishing infrastructure to target password vaults and cryptocurrency related assets.
Defender focus
- Monitor lookalike domains combining company names with terms such as login, help, security, passkey, or Okta.
- Treat unsolicited password-reset, emergency-access, and account-recovery calls as potential parts of a coordinated campaign.
- Protect cryptocurrency, SSO, help-desk, and password-manager identities with phishing-resistant authentication.
- Train support teams to recognize callers attempting to obtain credentials, reset links, authentication codes, or approval of access requests.
5. Darcula
Status: Actively evolving, with Darcula-like infrastructure observed in a major MEA phishing campaign between December 2025 and February 2026.
Darcula is a mobile-first phishing-as-a-service platform offering phishing templates that impersonate postal services, financial institutions, utilities, government bodies, airlines, and telecommunications providers. Netcraft has detected tens of thousands of related domains targeting brands and users across numerous countries.
Darcula-suite expanded this model by allowing operators to clone a legitimate website from a supplied URL. Browser automation tools can reproduce the site’s HTML, assets, and visual design before inserting forms that collect addresses, payment-card details, and authentication codes. This approach enables criminals with limited technical skills to create customized phishing pages for almost any brand.
In March 2026, Group-IB reported a large fake-shipment campaign targeting consumers across the Middle East and Africa. The attacks used urgent text messages claiming that a delivery had failed and instructed recipients to update their address or pay a small handling fee.
Attackers used local-looking numbers and spoofed Sender IDs, sometimes causing fraudulent messages to appear within existing conversations associated with trusted couriers. The links directed victims to phishing pages hosted on disposable domains using extensions such as .xyz, .help, and .shop.

Archived Darcula phishing templates impersonating international delivery services. Source.
Analysis of the pages uncovered persistent WebSocket connections that transmitted victims’ personal information, payment-card details, and one-time passwords to attacker-controlled servers as they were entered. Unique UUID tokens also allowed the operators to track individual phishing sessions.
It was found that many of the analyzed sites shared infrastructure and technical characteristics associated with Darcula. However, the researchers described Darcula as potentially involved and did not definitively attribute the entire campaign to its operators.
Defender focus
- Monitor lookalike courier domains, disposable domain registrations, and fraudulent delivery messages.
- Warn customers not to open shipment links received through unsolicited texts or messaging applications.
- Direct users to verify deliveries through the courier’s official website or mobile application.
- Detect persistent WebSocket connections and other real-time exfiltration behavior on newly registered domains.
- Maintain rapid reporting and takedown procedures because phishing domains can rotate quickly.
6. Evilginx
Status: Open-source security-testing framework repeatedly adapted for criminal phishing, with Evilginx-related tooling identified around The Quarry ecosystem in 2026.
Evilginx differs from a commercial phishing-as-a-service platform. It is an open-source reverse-proxy framework developed for authorized security testing, but attackers can modify it to reproduce legitimate authentication flows and intercept credentials, session cookies, or tokens. Capturing authenticated session material can provide account access even after a victim completes a conventional MFA challenge.

Evilginx interface displaying configurable phishlets for impersonated online services.
In June 2026, SOCRadar disclosed The Quarry, a modular phishing and malware-as-a-service operation active since at least April 2025. A developer using the alias RockyBelling sold phishing kits, cloaking infrastructure, bulk email tools, remote access panels, and post-exploitation scripts to nearly 200 operators.
The service primarily supported campaigns impersonating the IRS and Social Security Administration, although operators also used Microsoft, Adobe, DocuSign, and Dropbox lures. SOCRadar identified more than 80 domains, over 40 ScreenConnect panels, and more than 500 victim IP addresses across 14 countries. Over 90% of the observed victims were in the United States.
The Quarry’s catalog included a modified credential-harvesting panel that SOCRadar assessed as possibly derived from Evilginx. The operation’s broader attack chains also delivered ScreenConnect installers, used Adspect to hide phishing pages from researchers, and sent victim notifications through Telegram.
A subsequent Lexfo investigation found custom Evilginx forks used by three independent phishing operators. One exposed operator used MaDoO Blaster, a bulk-mailing tool promoted within The Quarry ecosystem. This evidence indicates a technical and commercial connection between Evilginx-based phishing infrastructure and The Quarry’s surrounding service market, but it does not establish that every Quarry campaign used Evilginx.
Defender focus
- Use phishing-resistant authentication such as FIDO2 security keys or passkeys for sensitive accounts.
- Monitor authentication behavior for stolen-session reuse, unusual token refreshes, and unfamiliar devices.
- Investigate unexpected ScreenConnect installations and connections to unapproved remote-access infrastructure.
- Monitor newly registered domains combining tax, IRS, SSA, estate, or trust terms with words such as portal, hub, archive, or guidance.
- Correlate phishing activity with Telegram traffic, cloaking behavior, and silent remote-management software installation.
7. EvilTokens
Status: Active device-code phishing service linked to a widespread Microsoft 365 campaign in 2026.
EvilTokens abuses Microsoft’s legitimate OAuth Device Authorization Grant rather than relying on a conventional credential-harvesting page. An attacker generates a valid device code and persuades the victim to enter it on Microsoft’s genuine authentication page. If the victim approves the request, the attacker receives access and refresh tokens without directly capturing the password.
In March 2026, Huntress attributed a large device-code phishing campaign to EvilTokens. The operation targeted around 344 organizations across the United States, Canada, Australia, New Zealand, and Germany, affecting businesses of different sizes and sectors.

SharePoint-themed phishing lure used in an EvilTokens device-code campaign. Source.
The campaign used personalized lures involving construction bids, DocuSign documents, voicemail notifications, business agreements, and Microsoft Forms. The research found no identical phishing messages in one wave spanning 344 organizations, indicating that automation or AI likely helped operators generate individualized content at scale.
Attackers used Railway infrastructure as a token-replay engine and concealed malicious destinations behind multi-stage redirect chains involving trusted services. Some EvilTokens pages also encrypt their phishing content and decrypt it only inside the victim’s browser, making the final page difficult for static URL scanners to inspect.
Defender focus
- Disable or restrict Device Code Flow when business operations do not require it.
- Train users never to enter a device code they did not personally request.
- Require compliant, managed devices for access to Microsoft 365.
- Monitor device-code authentication, unusual token refreshes, unfamiliar applications, and unexpected access locations.
- Revoke access and refresh tokens after suspected compromise; changing the password alone may not terminate access.
8. BlueKit
Status: Actively developed and advertised PhaaS platform, although confirmed victim campaigns remain limited.
BlueKit centralizes domain setup, phishing-page deployment, credential collection, and victim monitoring. Varonis identified more than 40 templates targeting services such as Gmail, Microsoft Outlook, iCloud, GitHub, ProtonMail, and Ledger. CloudSEK later reported 87 kits, suggesting that the platform’s inventory was expanding rapidly.
The dashboard can collect credentials, cookies, local-storage data, and active session information. It also provides antibot controls, device filtering, Telegram notifications, and peer-to-peer page rendering intended to conceal backend infrastructure.
In 2026, an underground forum advertisement promoted BlueKit as a reverse-proxy service capable of capturing authenticated session cookies. The operator also claimed support for automated domain registration, browser and geolocation spoofing, AI assistance, voice cloning, and enrollment of new authentication methods.
Independent research has confirmed several core platform features, but claims involving voice cloning and background passkey or 2FA enrollment remain unverified.
Defender focus
- Use phishing-resistant FIDO2 or WebAuthn authentication.
- Alert on unexpected passkey, MFA-method, and trusted-device registrations.
- Monitor session reuse, unusual browser fingerprints, and geographic changes.
- Avoid relying solely on static phishing-page fingerprints.
- Revoke active sessions after suspected compromise.
9. YY Lai Yu
Status: Active Chinese-language PhaaS platform targeting consumers across 119 countries, with its strongest focus on Japan.
Google Threat Intelligence Group documented YY Lai Yu in May 2026 as part of a growing Chinese-language phishing ecosystem. First advertised in August 2024, the service provides localized infrastructure that allows Chinese-speaking operators to target consumers in international markets.
Since November 2025, YY Lai Yu has offered more than 400 phishing templates. Its Japanese templates impersonate Amazon, Apple, JCB, Nintendo, PayPay, Rakuten, Mercari, financial institutions, transportation providers, and other widely used services.

YY Lai Yu phishing page impersonating Apple’s Japanese account portal. Source.
The platform’s lures reflect local consumer behavior and economic concerns. Campaigns have used expiring loyalty points, rewards, transportation services, online shopping, and government electricity subsidies to persuade victims to provide payment-card details and one-time passwords.
YY Lai Yu supports distribution through RCS and iMessage, live interaction with victims, domain management, geographic filtering, and payment-card filtering based on bank identification numbers. These features allow operators to localize and manage campaigns without developing their own infrastructure.
Defender focus
- Monitor localized domains impersonating Japanese financial, retail, payment, and transportation brands.
- Warn users about unsolicited loyalty-point, reward, and subsidy messages.
- Detect unusual payment-card provisioning and OTP requests.
- Strengthen on-device protection against links delivered through RCS and iMessage.
- Provide reporting channels and awareness materials in the languages used by targeted customers.
10. Telekopye
Status: Long-running Telegram-based toolkit used by organized scam groups since at least 2015.
Telekopye automates phishing campaigns targeting users of e-commerce and online marketplace platforms. Through its Telegram interface, operators can generate branded phishing pages, email and SMS messages, QR codes, and fabricated images of checks, receipts, and other financial documents.
The scammers, whom ESET calls “Neanderthals,” approach victims as prospective buyers or sellers before directing them to fraudulent payment pages. These pages collect payment-card details or online-banking credentials. Telekopye can also create domains that begin with the name of the impersonated platform, making malicious links appear more convincing at first glance.
SOCRadar’s analysis showed that Telekopye groups operate through a defined hierarchy of administrators, moderators, experienced workers, and regular participants. Stolen funds are transferred to an administrator-controlled account before operators request their share, with commissions ranging from 5% to 40%.

Telekopye’s link creation menu. Source.
Later campaigns expanded beyond marketplaces to target users of Booking.com and Airbnb. Attackers used compromised accommodation-provider accounts and genuine reservation details to send convincing payment-problem messages. This allowed the phishing requests to arrive through trusted booking-platform channels and reference real stays.
Defender focus
- Keep marketplace and booking conversations within the official platform.
- Verify payment requests through the platform’s application or customer-support service.
- Monitor partner and accommodation-provider accounts for unauthorized access.
- Warn users that genuine reservation details do not necessarily make a payment request legitimate.
- Detect lookalike domains that place the impersonated brand name at the beginning of a longer malicious address.
How Modern Kits Bypass MFA
MFA bypass is often an imprecise phrase. AiTM kits do not necessarily break the cryptography behind MFA. They relay the authentication flow and steal the authenticated session created after the victim completes the challenge. Device-code phishing takes a different path by persuading the victim to authorize an attacker-controlled session through a legitimate workflow.
These attacks are most effective against reusable or relayable factors, including passwords, SMS codes, one-time passwords, and push approvals. Phishing-resistant methods such as FIDO2 security keys and properly implemented passkeys bind authentication to the legitimate origin, making a reverse-proxy flow far harder to use successfully.
How Organizations Can Defend Against Phishing Kits
Strengthen Identity Controls
- Deploy phishing-resistant MFA for administrators, finance teams, executives, help-desk personnel, and other high-risk users.
- Require compliant devices and risk-based conditional access for sensitive applications.
- Limit device-code authorization, third-party OAuth consent, and legacy authentication.
- Revoke sessions and refresh tokens during response; do not rely on password resets alone.
Detect the Full Attack Chain
- Correlate email, DNS, proxy, endpoint, and identity telemetry instead of evaluating each alert alone.
- Inspect redirect chains, QR codes, HTML attachments, CAPTCHA gates, and links hosted on legitimate cloud services.
- Monitor for new inbox rules, OAuth grants, MFA-method changes, abnormal downloads, and impossible travel.
- Track lookalike domains and brand impersonation across the surface web, social platforms, app stores, and messaging channels.
Prepare for Account Takeover
- Create playbooks for session revocation, token invalidation, mailbox review, and affected-party notification.
- Verify payment and supplier changes through a separate trusted channel.
- Preserve evidence and search for persistence, lateral movement, data access, and secondary phishing sent from the account.
How SOCRadar CTI Security News Supports Phishing Monitoring
SOCRadar’s CTI Security News gives security teams a centralized view of emerging phishing campaigns, PhaaS platforms, identity threats, and changes in attacker techniques. Analysts can filter findings by threat type, industry, country, date, and other criteria while reviewing threat levels, confidence assessments, affected regions, and supporting references.

SOCRadar CTI Security News highlights YY Lai Yu activity and related phishing developments involving RCS and iMessage.
The YY Lai Yu example shows how teams can use Security News to follow a specific phishing service while also identifying related developments in delivery methods, targeting, and regional activity. This context can help analysts connect individual reports to broader trends and prioritize threats relevant to their users, brands, and industries.
CTI Security News should complement phishing-resistant authentication, secure email and web controls, identity monitoring, user reporting, and tested account-takeover response procedures.
Frequently Asked Questions
Can Phishing Kits Bypass MFA?
Some phishing kits can capture the authenticated session created after a victim completes MFA. They do not necessarily break the authentication method itself. Instead, AiTM platforms relay the login process and steal the resulting session cookie. Phishing-resistant methods such as FIDO2 and WebAuthn provide stronger protection against this technique.
How Does Device-Code Phishing Differ From AiTM Phishing?
AiTM phishing places a proxy between the victim and the legitimate authentication service. Device-code phishing instead persuades the victim to authorize an attacker-controlled session through a legitimate OAuth workflow. The victim may enter the code and complete authentication on a genuine Microsoft page, making URL checking insufficient.
Is a Phishing Kit the Same as Malware?
No. A phishing kit creates or operates deceptive pages and collection infrastructure, while malware executes on a device. A single campaign may use both. For example, a phishing page may steal credentials, deliver malware, or install remote-access software as part of a broader attack chain.
Does Checking the URL Stop Modern Phishing?
Checking the URL remains useful, but it is not sufficient. Attackers use compromised websites, redirect chains, lookalike domains, trusted cloud platforms, browser-in-the-browser windows, and legitimate device-authorization pages. Users should also verify whether they initiated the request and recognize the application or service requesting access.
What Are the Most Effective Defenses Against Phishing Kits?
Organizations should combine phishing-resistant authentication with managed devices, conditional access, email and web protection, brand monitoring, and identity-based detection. Response procedures should include revoking sessions and refresh tokens, reviewing newly registered authentication methods, and investigating activity performed through the compromised account.
Conclusion
Phishing kits have evolved into service ecosystems that automate page creation, infrastructure deployment, traffic filtering, victim interaction, and session theft. Tycoon2FA, EvilProxy, Sneaky 2FA, and EvilTokens demonstrate the continued importance of enterprise identity phishing. Evilginx shows how open-source security-testing frameworks can be adapted for criminal campaigns, while BlueKit illustrates the emergence of consolidated, all-in-one phishing platforms.
CryptoChameleon, Darcula, YY Lai Yu, and Telekopye extend the threat beyond corporate login pages. Their operators use mobile delivery, localized content, trusted consumer brands, marketplace conversations, and genuine account or reservation information to make fraud more convincing.
The practical response must be identity-centered and layered. Organizations should deploy phishing-resistant authentication, restrict risky authorization paths, monitor sessions after login, detect brand abuse early, and prepare to contain account takeover quickly. Kit names and infrastructure will change, but the underlying behaviors provide more durable detection opportunities.

