• Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions
No Result
View All Result
No Result
View All Result
Home Solutions News World | Latest Tech & Innovation Updates

A Million Phishing-as-a-Service Attacks Blocked In Two Months

SmartSolutionUser1 by SmartSolutionUser1
March 20, 2025
in Solutions News World | Latest Tech & Innovation Updates
0
A Million Phishing-as-a-Service Attacks Blocked In Two Months
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

In the first two months of 2025, Barracuda detection systems blocked over a million phishing attacks by prominent Phishing-as-a-Service (PhaaS) platforms. A new report on the tools and techniques used in the attacks highlights how PhaaS platforms are evolving rapidly to become more dangerous and evasive. Many target users of popular cloud-based platforms such as Microsoft 365.

You might also like

Calculus Partners with Aprecomm to Bring Next Generation AI-Powered Network Intelligence to ISPs Throughout MEA, Asia, and Latam

Tech Mahindra and DFKI Collaborate to Co-innovate and Co-create Smart Factory Solutions for German Enterprises

GoPro Unveils MAX2, LIT HERO, and Fluid Pro AI Cameras in India

Most (89%) of the detected incidents involved the sophisticated Tycoon 2FA, followed by EvilProxy, which accounted for 8% of attacks, and the newcomer, Sneaky 2FA, which was behind 3% of the incidents.

The three platforms have different and distinct toolsets, with some common elements such as the use of the Telegram messaging service to further attacks.

Tycoon 2FA – rapid innovation in evasion tools

Barracuda threat analysts reported on Tycoon 2FA in January 2025. Since then, the platform has continued to develop and enhance its evasive tactics, becoming even harder to detect.

Among other upgrades, the code script for credential theft and exfiltration is now encrypted and obfuscated using a substitution cypher and sometimes an invisible character (known as a Hangul Filler).

The new and enhanced script can identify a victim’s browser type to help with attack customization and features links to the Telegram service that can be used to secretly send stolen data to attackers.The script also enables parts of a web page to be updated independently of the rest of the page and includes AES encryption to disguise credentials before exfiltrating them to a remote server. All this makes detection by security tools far more difficult.

EvilProxy – a dangerously accessible tool

EvilProxy attacks can be implemented with minimal technical expertise. It targets widely used services such as Microsoft 365, Google, and other cloud-based platforms, tricking victims into entering their credentials into seemingly legitimate login pages.

The source code used by EvilProxy for its phishing webpage closely matches that of the original Microsoft login page. This makes it difficult to distinguish the malicious site from the original, legitimate website.

Sneaky 2FA fills in the phish form for victims

The third most prominent PhaaS in early 2025 was Sneaky 2FA, the platform for adversary-in-the-the-middle (AiTM) attacks targeting Microsoft 365 accounts in search of credentials and access. Like Tycoon 2FA, it leverages the messaging platform Telegram.

Sneaky 2FA checks to make sure the user is a legitimate target and not a security tool, bot or other adversary – if this is the case, the “victim” is redirected to a harmless site elsewhere – before pre-filling the fake phishing page with the victim’s email address by abusing Microsoft 365’s ‘autograb’ functionality.

“The platforms that power phishing-as-a-service are increasingly complex and evasive, making phishing attacks both harder for traditional security tools to detect and more powerful in terms of the damage they can do,” said Saravanan Mohankumar at Barracuda. “An advanced, multilayered defense strategy with AI/ML enabled detection, combined with a strong security culture and consistent security access and authentication policies, will help to protect organizations and employees against PhaaS based attacks.”

Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

Calculus Partners with Aprecomm to Bring Next Generation AI-Powered Network Intelligence to ISPs Throughout MEA, Asia, and Latam

by SmartSolutions
December 5, 2025
0
Calculus Partners with Aprecomm to Bring Next Generation AI-Powered Network Intelligence to ISPs Throughout MEA, Asia, and Latam

Calculus, a global leader in advanced network innovation, announced a strategic partnership with Aprecomm, a leading provider of intuitive, self-healing network and customer experience solutions. The collaboration sees...

Read moreDetails

Tech Mahindra and DFKI Collaborate to Co-innovate and Co-create Smart Factory Solutions for German Enterprises

by SmartSolutions
November 19, 2025
0
Tech Mahindra and DFKI Collaborate to Co-innovate and Co-create Smart Factory Solutions for German Enterprises

Tech Mahindra, a leading global provider of technology consulting and digital solutions to enterprises across industries, and Deutsches Forschungszentrum für Künstliche Intelligenz GmbH (DFKI), German Research Center for...

Read moreDetails

GoPro Unveils MAX2, LIT HERO, and Fluid Pro AI Cameras in India

by SmartSolutions
November 13, 2025
0
GoPro Unveils MAX2, LIT HERO, and Fluid Pro AI Cameras in India

GoPro announced the availability of its three new cameras in the Indian market. MAX2 – the highly anticipated next-generation GoPro 360 camera featuring Emmy® Award-Winning 360 Technology for...

Read moreDetails

Delvitech closes a $40 million investment round, among the most significant Deep Tech investments in Switzerland

by SmartSolutions
November 12, 2025
0
Delvitech closes a $40 million investment round, among the most significant Deep Tech investments in Switzerland

Delvitech, a Deep Tech company specializing in the development of AI-native Automated Optical Inspection (AOI) solutions for electronics, successfully closed a Series B investment round of USD 40...

Read moreDetails

SAP and Snowflake Partner to Unlock Enterprise AI and Data Potential Through a Unified Business Data Fabric

by SmartSolutions
November 12, 2025
0
SAP and Snowflake Partner to Unlock Enterprise AI and Data Potential Through a Unified Business Data Fabric

Snowflake, the AI Data Cloud company, and SAP SE, a global leader in enterprise applications and business AI, announced a new collaboration to enable organizations to seamlessly leverage...

Read moreDetails
Next Post
Bandhan Bank collaborates with Salesforce to drive digital transformation

Bandhan Bank collaborates with Salesforce to drive digital transformation

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Genesys Expands Collaboration with ServiceNow to Revolutionize AI-Powered Agent2Agent Customer Experience

Genesys Expands Collaboration with ServiceNow to Revolutionize AI-Powered Agent2Agent Customer Experience

September 13, 2025
Tenable Research Uncovers A Privilege Escalation Vulnerability In Google Cloud Run

Tenable Research Uncovers A Privilege Escalation Vulnerability In Google Cloud Run

April 2, 2025
Infopercept Unveils Invinsense 6.0

Commvault Partners with CrowdStrike

January 29, 2025

Browse by Category

  • Agora
  • AI
  • Article
  • AV Solutions
  • Business
  • Careers
  • Case Study
  • Cover Story
  • cyber security
  • EDU Solutions
  • Featured Article
  • Finance
  • Gartner
  • Global Academic
  • Health
  • Indian Government
  • Innovation
  • Interview
  • Interview
  • IT industry,
  • Jobs
  • Market
  • Networking
  • Nucleus Software
  • Open Ai
  • Politics
  • Products
  • Products Plus
  • projects
  • Security
  • SentinelOne®
  • Software
  • Solutions
  • Solutions Launch world
  • Solutions News World | Latest Tech & Innovation Updates
  • Startups
  • tech mahindra
  • Technology
  • Terafac Technologies
  • Uncategorized
Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

CATEGORIES

  • Agora
  • AI
  • Article
  • AV Solutions
  • Business
  • Careers
  • Case Study
  • Cover Story
  • cyber security
  • EDU Solutions
  • Featured Article
  • Finance
  • Gartner
  • Global Academic
  • Health
  • Indian Government
  • Innovation
  • Interview
  • Interview
  • IT industry,
  • Jobs
  • Market
  • Networking
  • Nucleus Software
  • Open Ai
  • Politics
  • Products
  • Products Plus
  • projects
  • Security
  • SentinelOne®
  • Software
  • Solutions
  • Solutions Launch world
  • Solutions News World | Latest Tech & Innovation Updates
  • Startups
  • tech mahindra
  • Technology
  • Terafac Technologies
  • Uncategorized

BROWSE BY TAG

Acquisition Adobe Agentic AI Agora AI Akamai AMD automation Cloudflare CloudKeeper CrowdStrike Cybersecurity Databricks Fortinet Gartner GenAI Google Cloud Hitachi Vantara Honeywell IBM Infosys Kaspersky Kramer LTIMindtree Microsoft New Relic NTT DATA Nvidia OpenAI Palo Alto Networks PPDS Qlik security ServiceNow smart solutions world smartsolutionsworld smart solutions world latest news Snowflake Software Sophos Tata Communications Tech Mahindra Technology Tenable Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions

© 2024 NCN - Premium news & magazine by NCN.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?