[weglot_switcher]
SpyCloud report on most active phishing kits in 2026 for cybersecurity.

The Most Active Phishing-as-a-Service Kits of 2026

Table of Contents

Check your exposure

TL;DR

What is phishing?

Phishing is a social engineering attack using fake outreach (emails, texts, spoofed pages) to trick targets into handing over credentials, session data, or other sensitive information. As one of the oldest and most persistent attack vectors in cybercrime, it is still one of the most effective. What’s changed is the sophistication of the infrastructure behind it. Attacks typically break down into three parts: the lure (what gets your attention), the hook (the spoofed landing page or trap you’re led to), and the payload (the actual collection of your data).

Ninety-four percent of Fortune 50 companies have had employee data exposed in a phishing attack.

What is phishing-as-a-service (PhaaS)?

Phishing isn’t just one of the longest standing plays in cybercrime, it’s also the single leading entry point for ransomware. Its widespread popularity and refusal to be out-evolved has led to the creation of an entire industry with the sole purpose of selling criminals neatly packaged schemes so they can get started without developing their own infrastructure. These products are called phishing-as-a-service (PhaaS) kits.

Some kits ship with full admin panels, the same way a software-as-a-service (SaaS) product would. Buyers can query for phishing data, manage domains, and assign permissions to their lackeys. Kits often come with support for buyers so they can get help with setup and troubleshooting. 

How PhaaS kits evolve

Modern PhaaS kits are out to get more than a password here or a credit card number there; they’re stealing sessions, which gives criminals access to more for longer. 

Modern kits use two primary methods to steal sessions:

Either way, the attacker ends up holding a live, already-logged-in session. It also means that remediation looks different. Teams need to revoke a session AND invalidate the token behind it. But with more than half of organizations saying they can’t pinpoint exactly which credential or token a given phish compromised, that’s easier said than done.

And even as organizations learn to respond quicker to today’s phishing attacks, the gap between safe and hooked continues to grow wider as the kits themselves keep getting more and more capable and the barrier to running them gets lower.  

More capable, easier-to-deploy kits are also giving attackers the confidence to go after higher-value targets. Enterprise sessions carry a higher return, and they’re now showing up in PhaaS-stolen data about 5 times more often than in malware logs.

Lastly, when a kit is successfully taken down or “offline”, it doesn’t stay gone. For example, Kali365, a kit that paired device-code and AiTM phishing against Microsoft 365, announced its own retirement after the FBI named it in a bulletin. Within days it rebranded as Green Octopus and resumed operations without any apparent interruption.

Kali365 is just one name on a growing list.

Top phishing-as-a-service kits

Below are some of the kits SpyCloud has tracked and analyzed this year, ordered by how closely we’ve covered them. Plus, a few more that have been floating around in the cybersecurity space. 

Kali365 (now Green Octopus), continued

Beyond the fake retirement, what made Kali365 dangerous was what happened after a victim was hooked. The kit paired stolen OAuth refresh tokens and session cookies with a desktop “token browser” that gave the buyer silent, one-click access to a victim’s Outlook, OneDrive, and SharePoint. A built-in “ghost mode” deleted multi-factor authentication (MFA) alerts and password-change emails from the victim’s inbox before they could see them, and a contact harvester with business email compromise (BEC) keyword monitoring let operators quietly watch for invoice and payment conversations to hijack.

Victims skewed toward small and mid-sized businesses in construction, manufacturing, healthcare, and professional services, the classic invoice-fraud target profile. And because operators reused compromised mailboxes to attack the victim’s own contacts and customers, the damage didn’t stop at the original target.

Read the full Kali365 analysis ->

Kali365 operators earned an estimated $200,000–$350,000 USD in subscription revenue from roughly 500 paying affiliates. 

Tycoon 2FA

Tycoon 2FA (tracked by Microsoft as Storm-1747) has run since August 2023, proxying real Microsoft 365 and Google Workspace login pages to capture usernames, passwords, MFA inputs, and session cookies in one pass. The kit’s victims skewed heavily towards the US, UK, and Canada, and login activity into the admin panel itself was almost entirely masked.

In March 2026, Europol and Microsoft led a coordinated seizure of the infrastructure behind Tycoon 2FA, with SpyCloud contributing victim intelligence and operational metrics.

Read the full Tycoon 2FA analysis ->

SpyCloud identified 328,865 victim records tied to Tycoon 2FA, with approximately 80% belonging to enterprise-managed email domains.

Darcula (V3)

Darcula built its name on “missing package” smishing campaigns, texts impersonating postal services around the world to steal personal information and payment details. Its V3 update turned it into something closer to a phishing kit factory. A buyer submits any brand’s URL and the platform automates capturing the site’s logos, fonts, and layout to generate a working, custom-branded phishing kit. 

It’s the kind of tool that hands even low-skill operators everything they need to launch their own wave of attacks. SpyCloud named Darcula, along with Tycoon 2FA and FlowerStorm, among the AiTM platforms behind a 10-point year-over-year rise in phishing-driven ransomware attacks. 

YYlaiyu

YYlaiyu is a Chinese-language PhaaS panel built for financial fraud, distributed to actors who target victims through smishing, phishing sent by text rather than email, over iMessage and Rich Communication Services (RCS). What makes YYlaiyu different from other kits is how hands on it lets operators be. The panel alerts a phisher the moment someone lands on one of their pages, letting them manually prompt that victim for a one-time passcode (OTP) or card number in real time, all while an integration with Alibaba’s domain registration service lets them register and manage new phishing domains without needing to leave the panel.

Read the full YYlaiyu analysis ->

The YYlaiyu panel offers more than 90 custom phishing page templates impersonating brands across shipping, airline, banking, and cryptocurrency platforms.

Jalisco

Device-code phishing normally comes with a built-in expiration. Microsoft’s codes are only good for 15 minutes, so a lure sitting unopened in an inbox eventually goes dead. Jalisco, identified by ReliaQuest in July 2026, gets around that by calling a backend API to mint a fresh device code the moment a victim opens the page – keeping the clock from ever running out. Once the victim signs in and clears MFA, the operator enrolls an attacker-controlled device into the victim’s Entra ID tenant and walks away with a primary refresh token, one that keeps working even after the victim resets their password.

Per ReliaQuest’s research, Jalisco operators registered five or more attacker-controlled devices per compromised account, naming them to blend in with legitimate entries, like “microsoft-” and “WINDOWS-”.

OmegaLord

Where Jalisco plays the long game with device-code tokens, OmegaLord, also identified by ReliaQuest in July 2026, takes a more straightforward approach. It disguises itself as a PDF-reader login page and runs as a straightforward JavaScript credential harvester, grabbing the victim’s password alongside their phone number. The phone number captured is then likely used for intercepting MFA codes sent via text once a stolen password gets used. 

Honorable mention PhaaS kits

FlowerStorm: An AiTM kit named alongside Tycoon 2FA and Darcula as one of the phishing-as-a-service platforms behind 2025’s rise in phishing-driven ransomware attacks.

Kratos: A rival AiTM kit that SpyCloud found Kali365 affiliates running in parallel, treating both as interchangeable tools for the same phishing pipeline.

Nova: Another kit in that same rotation, run alongside Kali365 and Kratos by affiliates who don’t stick to a single platform.

Dadsec (Dadsec OTT): The phishing kit researchers believe Tycoon 2FA was originally built from, based on strong code similarities identified by Sekoia.

Lighthouse: A Chinese-developed kit used for fake toll-violation smishing and ecommerce and banking impersonation, per Krebs on Security’s reporting.

Haozi (Magic Mouse): A plug-and-play Chinese PhaaS kit with a low technical barrier and active customer support, letting less experienced operators run campaigns, per Netcraft’s research.

Lucid: A Chinese PhaaS panel known for granular, role-based permissions that separate administrators, employees, and guest users, per Prodaft’s research.

See how PhaaS kits are targeting your organization

The data PhaaS operators have already harvested may include credentials and sessions tied to your employees and customers.

FAQs

There is no single “best” phishing tool – kits like Tycoon 2FA, Darcula V3, and Kali365 (now Green Octopus) each dominate different segments, with Tycoon 2FA capturing 328,865 victim records before its March 2026 takedown and Darcula V3 automating custom-branded phishing pages for any target URL.

Stolen data moves fast into criminal markets: credentials get sold or tested against other services, session cookies get loaded into anti-detect browsers for direct account access, and everything gets folded into larger identity datasets used for fraud and follow-on attacks.

Kits like Kali365 specifically hunted invoice and payment conversations, making businesses that rely on high-value financial transactions, including manufacturing, healthcare, and financial services, prime targets. Enterprise environments are particularly at risk: enterprise sessions now appear in PhaaS-stolen data about five times more often than in malware logs, and compromised mailboxes are routinely reused to attack a victim organization’s own vendors and customers.

Not permanently. Europol’s March 2026 seizure of Tycoon 2FA’s infrastructure cut newly recaptured credentials by roughly 41% in the week that followed, a real disruption. But Kali365 proved the other side of that coin: it faked its own retirement after an FBI bulletin, then kept operating under a new name, Green Octopus, without a day of downtime.

AiTM kits proxy a fake login page between the victim and the real one, capturing credentials and the session cookie as the exchange happens. Device-code kits skip the fake page entirely: they send the victim to a real login page and trick them into entering an attacker-generated code, so the resulting token goes to the attacker’s device instead of the victim’s.

No, and that’s the point of these kits. Both techniques capture a session after MFA has already been satisfied, so from the application’s perspective, nothing looks wrong. There’s no failed login or second MFA prompt to flag.

Increasingly fast. AI has compressed what used to take hours of manual mailbox review, finding live invoice threads, drafting a convincing reply, into minutes, shrinking the window defenders have between compromise and damage.

No. Because these kits steal the session or refresh token rather than the password, resetting the password alone leaves the stolen token valid. Full remediation requires explicitly revoking the session and invalidating the token behind it.

Device-code phishing and adversary-in-the-middle (AiTM) attacks lead 2026’s phishing landscape, with kits like Jalisco minting fresh device codes on-demand to bypass expiration timers and operators enrolling attacker-controlled devices directly into victims’ Entra ID tenants to maintain access even after password resets.

Keep reading

Analysis of Stealc malware takedown by SpyCloud for cybersecurity.
Peers Held, StealC Didn’t: Analyzing the June 24 Takedown in SpyCloud’s Data
SpyCloud Labs data shows StealC fell 90% before the June 24 Operation Endgame takedown. See what our post-takedown analysis reveals.
SpyCloud logo with FortiBleed threat actor infrastructure background.
More Than a Leak: What SpyCloud Found Inside the FortiBleed Threat Actor Infrastructure
SpyCloud Labs analyzed the media-dubbed “FortiBleed” leak and found that initial reports left some key information out. See what we found after parsing and analyzing the data to understand the full impact.
Kali365 PhaaS kit overview for cybersecurity and threat detection.
Kali365: Anatomy of a Microsoft 365 Phishing-as-a-Service Kit – From Telegram Hype to FBI Takedown Theater
SpyCloud researchers dissect Kali365, a Telegram-sold phishing-as-a-service kit targeting Microsoft 365. Using device-code and adversary-in-the-middle phishing, it steals OAuth tokens and session cookies to bypass MFA – then staged a fake FBI "shutdown" while operations continued. Here's how the kit works, who it targets, and why password resets won't stop it.

Check Your Company's Exposure

See your real-time exposure details powered by SpyCloud.

X