criticalLast updated: June 2026

Phishing Kit Evolution

Modern phishing kits mirror brand experiences, proxy live sessions, and capture one-time codes in real time.

Get the CSM Weekly Threat Brief and updates when this threat profile changes.

What\'s happening

Adversary-in-the-middle phishing kits proxy the legitimate login flow and relay credentials plus OTPs live.

Victims are lured through targeted copy, cloned landing pages, and domain variants that look correct at a glance.

These kits are increasingly sold as subscription offerings with dashboards and support.

Who it targets

Microsoft 365 and Google Workspace users

Remote teams and contractors

Consumers responding to account alerts and package texts

Real-world examples

Session cookies stolen even after MFA entry.

Password reset prompts sent immediately after a fake admin alert.

Phishing-as-a-service operators selling customizable kits by brand.

What it costs

Mailbox compromise often becomes the gateway to wider fraud.

Session theft can bypass traditional credential reset approaches.

Organizations face follow-on attacks from the same mailbox.

How to protect against it

Adopt phishing-resistant MFA where possible.

Deploy email and web filtering against lookalike domains.

Train users on proxy-style phishing behavior.

Monitor session anomalies and impossible device changes.

Vendors who specialize in this threat

BrightMail Shield

Email Security & Anti-Phishing

Inbox defense, domain impersonation monitoring, and phishing disruption.

Find More Vendors for This Threat

VaultKey

Identity & Access Management

MFA, privileged access, and passwordless identity workflows for growing businesses.

Find More Vendors for This Threat

AwareLine Training

Security Awareness Training

Behavior-focused training for phishing, social engineering, and policy hygiene.

Find More Vendors for This Threat

Related threats

Emerging / AI-Powered Threatscritical

AI-Powered Phishing

LLMs are enabling more targeted, more fluent, and more personalized phishing at industrial scale.

Stat: LLMs used to generate hyper-personalized attacks

Read Full Brief
Financial Attackscritical

CEO Fraud / BEC Scams

Email compromise and impersonation attacks are targeting payment approvals, invoice changes, and executive requests.

Stat: $2.9B lost in 2023 (FBI IC3)

Read Full Brief
Identity & Accesscritical

Credential Stuffing

Attackers are replaying massive stolen credential sets across business and consumer services to hijack accounts at scale.

Stat: 24B credentials available on dark web

Read Full Brief