Do you have 500 dollars? That’s enough to buy a PhaaS kit, spin up a campaign, and start targeting real users across Microsoft 365, Google Workspace, and other cloud environments. What used to require bespoke infrastructure, custom phishing pages, and deep technical skills is now available as a subscription service with a slick dashboard, customer support, and “how‑to” guides.
This democratization of phishing isn’t just lowering the barrier to entry for cybercrime but also enabling mass cloud compromise.
Phishing-as-a-Service (PhaaS) democratization marks one of the most important changes in the cybercrime economy since the emergence of Ransomware-as-a-Service (RaaS). What was once a specialized craft that required advanced skills and significant resources, limited to sophisticated criminal groups and advanced persistent threat (APT) actors, has now become a fully commoditized, subscription-based service. Today, even low-skilled operators, script kiddies, and opportunistic criminals can easily access it.
At its core, PhaaS democratization is the process of packaging powerful phishing capabilities into simple, ready-to-use platforms. These platforms include Adversary-in-the-Middle (AiTM) proxies, OAuth device-code abuse, session hijacking, and advanced techniques for bypassing multi-factor authentication (MFA). Previously, launching such attacks demanded months of technical expertise and custom infrastructure. Now, anyone can gain access through a monthly subscription, typically priced between $100 and $2000 in cryptocurrency. Each subscription provides clean web dashboards, automated campaign tools, and strong evasion features.
This transformation has been driven by three key factors:
- The Growth of the Crime-as-a-Service (CaaS) Model: Inspired by successful RaaS operations such as LockBit and Conti, PhaaS creators have established a clear division of roles. Core developers build and maintain the platform, while affiliates simply rent it and run campaigns.
- The Integration of Generative AI: Modern kits now embed LLMs, including uncensored models such as Llama. These AI systems automate critical tasks like hyper-personalized email writing, polymorphic content creation, OSINT-based targeting, and even follow-up BEC messages. This has dramatically increased both the scale and the success rate of attacks.
- The Shift Toward Advanced Attack Primitives: Modern PhaaS kits now focus on token-centric attacks, particularly the abuse of OAuth device authorization grants. By leveraging legitimate identity provider flows such as microsoft.com/devicelogin, these kits can bypass many Conditional Access policies and some phishing-resistant controls.
The outcome is a striking imbalance in the threat landscape. Defenders now face an exponential rise in attack volume, while attackers enjoy industrialized tooling, fast iteration, and very low costs. According to threat intelligence reports from 2025–2026, more than 85–90% of high-volume phishing campaigns now rely on PhaaS infrastructure. Certain kits, such as EvilTokens, Kali365, and Bluekit, regularly achieve success rates that were once seen only in targeted APT operations.
This introduction lays the foundation for a deeper technical discussion of PhaaS architecture, core attack techniques (AiTM, device code flow, and token theft), the role of AI components, advanced evasion strategies, and most importantly, the defensive countermeasures needed in this new post-democratization era.
Emerging PhaaS Kits in 2026
The first half of 2026 has seen a surge in new and evolved PhaaS platforms that continue to advance democratization. These kits focus heavily on token-centric attacks, deep AI integration, and advanced anti-analysis features, shifting away from simple credential theft toward persistent, stealthy account takeovers.
Kali365, which emerged in April 2026, quickly became one of the most discussed kits after receiving an official FBI warning in May. It specializes in OAuth device code phishing by abusing the legitimate Microsoft device authorization flow (microsoft.com/devicelogin). The platform offers AI-generated lures, automated templates, and real-time dashboards that enable even low-skilled operators to capture persistent OAuth access and refresh tokens without relying on fake login pages.
Full analysis of Kali365 with attack methods, behavior, etc.
EvilTokens, launched in March 2026, stands out for its strong AI capabilities. It combines device code attacks with automated post-compromise features, using LLMs to generate personalized follow-up emails and perform mailbox triage for BEC fraud.
Other notable emerging kits include Whisper 2FA (AiTM focused), Phoenix System (large-scale smishing), and Cephas, CoGUI, and GhostFrame (heavy obfuscation and Microsoft API integration). Most of these platforms now embed uncensored LLMs, such as the Llama model, directly into the operator dashboard.
This new generation of kits has helped drive the statistic that 85–90% of high-volume phishing campaigns now rely on PhaaS infrastructure. Their rapid iteration and low barrier to entry continue to significantly challenge defenders.
This rapid proliferation of advanced kits clearly demonstrates the continued democratization of PhaaS, as highly sophisticated tools become easier to access and operate for a growing number of low-skilled cybercriminals.
The top tools we’ve been tracking in recent months include some of the most aggressive ones. These tools have shown rapid evolution in capabilities, adoption, and impact, making them especially important for us to monitor closely.
Unique Aspects of PhaaS Democratization
Here’s what sets it apart from traditional phishing and other CaaS models. Unlike conventional offerings that focus on simple payload delivery or basic phishing kits, this ecosystem provides full operational support, continuous updates, and built-in evasion techniques. It lowers the barrier to entry for less experienced attackers while enabling highly scalable, automated campaigns that are harder to detect and defend against.
Low skill required
Where traditional phishing demanded coding skills, server management, strong social engineering, and deep evasion expertise, PhaaS compresses all of that into a point‑and‑click workflow. Operators get intuitive dashboards, ready‑made templates, fully managed infrastructure, and powerful automation. As a result, even non‑technical actors can run advanced, large‑scale campaigns that circumvent MFA using AiTM techniques.
Subscription Model
Unlike one-off phishing kits or standalone malware, PhaaS operators offer a full-service, subscription-based ecosystem. Instead of just selling a kit, they provide persistent infrastructure, frequent updates to evade new detections, “customer” support, real-time victim and credential tracking, and built-in campaign orchestration.

AI acceleration
Many modern PhaaS kits embed generative AI directly into the attack workflow, automatically producing hyper‑personalized lures, polished and grammatically correct emails, synthetic identities and deepfakes, and continuously adaptive phishing flows. This makes campaigns more convincing, more resilient to traditional content‑based detections, and far more scalable than what human operators could manage manually.
Proliferation & Scale
The number of active PhaaS kits roughly doubled, and an estimated 90% of high‑volume phishing campaigns are now powered by them. From a cyber‑defense perspective, this represents a clear industrialization of the phishing ecosystem: turnkey, cloud‑hosted platforms are scaling attacker operations in the same way SaaS scaled legitimate businesses. Thousands of low‑skill actors can now run “enterprise‑grade” phishing at scale, with load‑balanced infrastructure, automated failover between kits or domains, integrated proxying for AiTM, and real‑time telemetry on victim interactions.
Role separation
Skilled developers focus on building, hardening, and maintaining the PhaaS platform, while anyone with money can effectively become an “attacker” by operating it. This separation of duties mirrors legitimate SaaS models and fuels an efficient underground economy, with clearly defined roles for core developers, affiliates, resellers, access brokers, and campaign operators. Each group specializes in a specific phase of the kill chain, whether development, distribution, access, or execution, and collectively drives scale, reliability, and rapid innovation on the attacker side while complicating attribution and takedown efforts for defenders.
How AI Drives Democratization
AI has become the primary catalyst accelerating PhaaS democratization in 2025–2026. By removing technical and creative barriers, AI transforms complex phishing operations into simple, accessible tasks that require minimal expertise.
Modern PhaaS kits embed LLMs directly into their dashboards, enabling operators to generate hyper-personalized phishing content at scale. These models perform OSINT scraping, craft convincing email lures, localize content across multiple languages, and automatically create thousands of polymorphic variants to evade detection systems. Beyond content creation, AI powers real-time campaign optimization, adaptive evasion techniques, and even post-compromise automation such as mailbox triage and Business Email Compromise messaging.

The most powerful aspect is the dramatic reduction in required skills. What once demanded weeks of manual effort from experienced social engineers can now be completed in minutes by complete beginners.
Example: In Kali365, an operator simply types “Create an urgent finance invoice email for a procurement manager at Acme Corp” into the built-in AI assistant. The system instantly generates a perfectly worded email referencing recent company events, includes a legitimate Microsoft device code link, and produces multiple variations. The entire campaign from lure creation to deployment can be launched within minutes, achieving success rates that previously required expert-level attackers.
This fusion of speed, intelligence, and ease of use has lowered the barrier to entry so significantly that PhaaS has truly become available to the masses.
The Economic Model Behind PhaaS Democratization
PhaaS has adopted a highly efficient Crime-as-a-Service (CaaS) franchise model that mirrors legitimate SaaS businesses. This model is the core engine driving democratization by separating responsibilities and minimizing risk for all participants.
At the top of the hierarchy are the core developers with small, skilled teams (often 2–8 people) who design, code, and continuously update the PhaaS platform. They handle complex tasks such as building reverse proxies, integrating new AI models, developing evasion techniques, maintaining infrastructure, and responding to law enforcement takedowns.
Below them are the affiliates, the actual operators. These are typically low-skilled cybercriminals, script kiddies, or small criminal groups who simply rent access to the platform. They do not need to understand the underlying code or maintain servers. Their only job is to run campaigns, compromise accounts, and monetize the stolen data.
Pricing Structure (as of mid-2026)
Basic Tier ($100 – $300 per month): Access to standard templates, basic AiTM and Device Code functionality, limited AI lure generation, and community support.
Pro Tier ($400 – $800 per month): Full AI capabilities (including Abliterated Llama or equivalent), advanced automation, polymorphic content generation, real-time campaign analytics, priority support, and access to the latest evasion modules.
Enterprise / Private Tier ($1,000 – $3,000+ per month): Dedicated private instances, custom feature development, exclusive zero-day techniques, managed campaign services, and higher success rate guarantees. Some operators even offer revenue-sharing affiliate programs.
Note: Almost every feature in these PhaaS kits is strictly dependent on the subscription tier. For example, advanced AI personalization, LLM access, automated post-exploitation, and premium evasion modules are available only on the plans.
Attack Behavior
The attack behavior of modern PhaaS kits, particularly those in the OAuth-MS-Phish category, follows a highly structured and efficient lifecycle designed for maximum success with minimum detection.
A typical campaign starts with AI-assisted reconnaissance and the creation of personalized lures. After the victim successfully authenticates via either the Device Code flow or an AiTM proxy, the kit immediately transitions to automated post-compromise actions.
Common Post-Exploitation Behaviors include:
- Registering a new device – The kit registers the attacker’s browser or device as trusted to maintain long-term access.
- Creating inbox rules – Attackers automatically create hidden forwarding rules to exfiltrate emails or monitor communications without raising suspicion.
- Adding new authentication methods – They register additional MFA methods (e.g., a new phone number or authenticator app) to ensure persistent access even if the victim resets their password.
- Changing the account password: In many cases, the attacker changes the password to lock out the legitimate user while maintaining control via tokens.
- Exfiltrating SharePoint Online (SPO) files – The kit systematically downloads sensitive documents from OneDrive and SharePoint, focusing on financial reports, contracts, and credential files.
- Microsoft Graph reconnaissance – Enumerates mailbox contents, contacts, calendar events, Teams messages, and user permissions.
- Privilege escalation & role abuse – Checks for and abuses admin roles or consents to expand access.
- Lateral movement – Uses compromised accounts to send internal phishing or target connected services.
These actions are often fully automated. Kits like EvilTokens and Bluekit perform mailbox triage, identify high-value content, and exfiltrate data silently in the background. Most kits also support rapid infrastructure rotation, dynamic subdomains, geofencing, and browser fingerprint validation to avoid detection.
No Slack account needed.
How it looks in Entra ID
From the attacker’s perspective, I already had a valid refresh token for the user, with MFA previously satisfied, so I can use the Microsoft Authentication Broker to silently redeem it and bypass any new MFA challenge.
The first attempt to use the broker failed with error 50199, likely due to a conditional access or transient issue. I quickly retried and successfully obtained a new access token that met the MFA requirement via a claim in the token. With that token, I then accessed OfficeHome as the victim, appearing as a normal, successful sign-in.
Then, the attacker abused the device code flow to sign in as the victim through the Microsoft Authentication Broker. I presented a device code to the user and had them approve it on a legitimate Microsoft page. In the logs, this appears as a mobile app and a desktop client signing in to Microsoft Graph using the Device Code authentication protocol. Once the device code was authorized, I silently obtained tokens and maintained my own session as the user.
After obtaining the victim’s tokens, the attacker registered a Windows device into the tenant to make my access look legitimate and persistent. Using the same compromised context, he triggered a Register device operation, which shows in the audit logs under Device Registration Service / Category: Device / Activity type: Register device.
The User Agent appears as a normal Windows dsreg client (Dsreg/10.0 (Windows 10.0.19045.2006)), so the action blends in with standard Azure AD Join/workplace join activity. This newly registered device can now be leveraged to satisfy device-based policies or appear as a trusted, compliant endpoint for future attacks.
Guardz ITDR
Guardz ITDR saw a token theft alert via device code flow for the user. Within seconds of a legitimate interactive login, the user’s freshly authenticated session was consumed again from a second, never‑before‑seen IP.
Guardz noted that this second IP used Microsoft Authentication Broker, an application never observed in the tenant, and that no device OS was reported, which is highly atypical for normal user activity. Finally, ITDR saw that the session from this new IP completed successfully without a fresh MFA challenge, indicating token replay instead of a standard user sign‑in, and escalated it as “Potential OAuth Token Theft via Device
Guardz first detected a Browser AiTM Session Replay Attack targeting the user, indicating that the attacker had hijacked a live browser session. In the same minute, it then raised “Potential OAuth Token Theft via Device Code Flow by Users”, correlating that the stolen, freshly authenticated session was being reused via device code flow and Microsoft Authentication Broker.
Guardz saw that right after a legitimate interactive sign-in, the same freshly authenticated session for the targeted user was consumed from a second, never-before-seen IP. That second IP used Microsoft Authentication Broker, an app never previously observed in the org, to complete a device code flow against Microsoft Graph. In Entra logs, MFA was marked as satisfied “by claim in the token,” meaning no fresh MFA challenge occurred despite the new IP and client.
Guardz ITDR combined these signals, new IP, new OAuth client, device-code protocol, session reuse without MFA, and raised the “Potential OAuth Token Theft via Device Code Flow by Users” high‑risk incident, then triggered automated session revocation.
Related Articles