INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Phishing platforms and infostealers linked to identity attacks surge
| 2025-07-07 12:00 CRITICAL HIGH DATA BREACH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A 156 percent jump in cyberattacks targeting user logins has been reported since last year, with identity-based attacks now making up 59 percent of all investigations carried out by security experts. The rise is attributed to advanced phishing kits and info-stealing malware, particularly phishing-as-a-service platforms such as Tycoon 2FA that offer convincing pre-made phishing pages for major workplace platforms at a relatively low cost of $200-300 per month. These services have emerged as the dominant phishing tool since its release in 2023, with over 2,000 monthly subscribers, and are capable of stealing session cookies and bypassing MFA. The attacks often lead to business email compromise (BEC) schemes and ransomware disasters, which can result in significant financial losses for organizations, estimated to be deep into the 10-digit range.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in-
• Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation.
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
Global Scope
financefinance
Incident Timeline
2025/07/07
Phishing-as-a-service platforms such as Tycoon 2FA are democratizing identity attacks thanks to their sophisticated capabilities and relatively low cost.
Click on any entity below to view its context and source!
threat_actor
Scattered Spider
Figures from last year
showed
that BEC attacks, cases involving the impersonation of support staff a la Scattered Spider, and even investment fraud, all contributed to greater financial losses, deep into the 10-digit range.
infrastructure
Microsoft 365
…-300 per month, these kinds of toolkits offer convincing pre-made phishing pages for the major workplace platforms, such as Microsoft 365 and Google Workspace, as well as adversary-in-the-middle (AitM) functions to steal session cookies and bypass…
financial
300 $ outlay
And for those who can't afford the $200-300 outlay for Tycoon 2FA, that's where infostealers come into play.
financial
$10 Entities
As little as $10 can unlock access to various logs gathered by info-grabbing malware, offering a more hands-off approach to email compromise.
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
…-300 per month, these kinds of toolkits offer convincing pre-made phishing pages for the major workplace platforms, such as Microsoft 365 and Google Workspace, as well as adversary-in-the-middle (AitM) functions to steal session cookies and bypass…
Metrics
financial
300
$ Outlay
And for those who can't afford the $200-300 outlay for Tycoon 2FA, that's where infostealers come into play.
Metrics
financial
10
Financial Impact
As little as $10 can unlock access to various logs gathered by info-grabbing malware, offering a more hands-off approach to email compromise.
Intelligence Sources
The Register - CSO
2025-07-07
Phishing platforms, infostealers blamed as identity attacks soar
The Register - CSO
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:38
Comprehensive Tactical Telemetry
Highly Correlated Entities
9x
organisation
Identified Entity
BEC
entity
4x
general metric
Percent
156
percent
3x
tactic
Cyber Operation Type
Phishing
tactic
3x
timeline
Temporal Reference
2024/07/07
date
2x
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
2x
attribution
Attributing Entity
FBI
authority
Contextual Telemetry
Context Block
7 METRICS
threat actor
APT Group
Scattered Spider
actor
general metric
Digit
10
digit
infrastructure
Affected Product
Microsoft 365
software
general metric
Microsoft
365
microsoft
general metric
Leaked Passwords Story
16,000,000,000
leaked passwords story
financial
$ Outlay
300
$ outlay
financial
Financial Impact
10
entities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.