• 'Organised crime operating like a tech startup': EvilToken PHaaS

    From TechnologyDaily@1337:1/100 to All on Wednesday, June 24, 2026 13:30:26
    'Organised crime operating like a tech startup': EvilToken PHaaS group ramp
    up AI-enabled attacks by 1,380% in 2026

    Date:
    Wed, 24 Jun 2026 12:15:00 +0000

    Description:
    AI is used for more than just scaling - it enabled personalization at an unprecedented level.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Huntress report highlights EvilTokens PhaaS scaling phishing attacks 1,380% in early 2026 compared to last year AI integration enables pervictim personalization at scale,
    bypassing MFA, with subscription tiers from $600 to $1,500 Service sold
    openly on Telegram, showing how PhaaS now operates like a startup with cheap, powerful attack capabilities Cybercriminals offering phishing-as-a-service (PhaaS) are increasingly operating like a tech startup, and a good one, at that. They are also using Artificial Intelligence (AI), which helped them scale significantly. This is according to a new report from cybersecurity researchers Huntress, called EvilTokens and the Rise of AI-Powered Phishing.

    In the report, Huntress claims that this particular PhaaS operation, called EvilTokens, was used to run 1,380% more phishing attacks in early 2026 compared to the same period last year. Were seeing a clear maturation of the phishing-as-a-service (PhaaS) market as threat actors increasingly integrate AI workflows into their product offerings, the report reads. The result is directly observable in our telemetry: a 1,380% increase in device code phishing attacks detected between JulyDecember 2025 and JanuaryApril 2026, with over 50% of those incidents linked to two major waves of correlated incidents. Latest Videos From Watch full video here: A cheap service Furthermore, across hundreds of incidents associated with EvilTokens, no two phishing lures were identical. This level of per-victim personalization was previously limited to targeted, manually crafted campaigns. Now, its achievable at scale by any threat actor at the price of a subscription
    service

    So, AI is not only used to scale the operation, but it is also used for personalization at an unprecedented level. At the same time, the service is relatively cheap to use: it is being sold on Telegram for as little as $600. You may like The vast majority of phishing attacks are now generated by AI, experts warn The fake Rolex problem: How AI turned amateur attackers into nation-state threats How businesses can defend themselves against the rise of phishing as a service

    If this sounds like a lot, keep in mind that a single successful phishing attack is enough to steal data worth hundreds of thousands on the black market, or even millions - in ransom negotiations.

    EvilTokens service is tiered, too. The cheapest package costs $600, while two more expensive ones cost $1,000 and $1,500, respectively. For criminals, it
    is likely worth the investment, since this PhaaS is capable of bypassing multi-factor authentication, as well. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
    with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. The
    best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/organised-crime-operating-like-a-tech-s tartup-eviltoken-phaas-group-ramp-up-ai-enabled-attacks-by-1-380-percent-in-20 26


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)