Save your seat →

Push Logo

Browser threat landscape: mid-year update 2026

Dan Green
Dan Green
·
Aug 10, 2026
·
12 min read

PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.

Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.


The SLH playbook becomes the industry standard

Criminals associated with "The Com," broadly known as the Scattered Lapsus$ Hunters collective, have spent the past three years establishing a playbook focused on identity compromise and cloud data theft for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).

Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, SLH-affiliated groups are responsible for roughly 70%.

 Public breaches and campaigns with a browser and identity-related breach vector in 2026.
Public breaches and campaigns with a browser and identity-related breach vector in 2026.

The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in tricking help desks into performing account resets. This year, they've switched to using voice-based lures in tandem with browser-based phishing payloads — usually impersonating IT staff under the guise of "setting up passkeys."

The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: Panera Bread (~14M records), Match Group (Hinge, Tinder, OkCupid; 10M+ records), Betterment (~20M records), Odido (6.2M Dutch telecom customers with BSNs and IBANs exposed), ADT (5.5M records), Charter Communications (4.9M accounts), Carnival Corporation (6M records), and Pitney Bowes (8.2M emails per HIBP). Optimizely is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.

Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal device code phishing campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like Salesloft, Drift, and GainSight and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since repeated at scale.

Copycats and nation-state adoption

Wider groups are now running the SLH playbook independently. Pink (the latest rebrand in the BlackFile-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. Helix also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. KongTuke, an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.

It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used compromised hotel and conference Wi-Fi gateways to direct victims to AiTM, ClickFix, and device code phishing pages. And Google Threat Intelligence mapped a dozen Chinese-language PhaaS platforms with real-time MFA interception.

"The Com" affiliates increasingly set the playbook for other criminal groups, and even nation-state operators. It might not always be super sophisticated, but they've proven the playbook works. And from the APT's perspective, why burn an exploit if you can achieve the same with a phish kit?


Phishing infrastructure has reached an industrial scale

The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.

Device code phishing goes mainstream

We're tracking a huge spike in device code phishing since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.

What began with Storm-2372's nation-state campaigns in August 2024 has proliferated through criminal kits like EvilTokens (340+ organizations in its first five weeks), Kali365 (which earned an FBI public advisory), ARToken, DEBULL, Forg365, and many more.

Detections by device code phishing kit. Kits are multiplying and fragmenting each month, with a long tail of kits not named here.
Detections by device code phishing kit. Kits are multiplying and fragmenting each month, with a long tail of kits not named here.

The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.

Established AiTM vendors like Tycoon 2FA have added device code phishing alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.

Tycoon is a particularly notable example because following a public takedown of its AiTM infrastructure, some recent reports have Tycoon detections dropping, but we're finding that actually Tycoon device code attacks in particular have bounced back in our detections.

When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.

Push Security detections by phishing kit, April-June 2026
Push Security detections by phishing kit, April-June 2026

PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.

And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.

PhaaS platform evolution and evasion

The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include Bluekit, Blacksite and Cloaked.gg — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and WackoGinx, a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.

Sneaky 2FA changes have also been documented, with what ZeroBEC calls "route polymorphism" (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting split-click buttons and blob URLs designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page).

The speed of technique adoption across these platforms is itself accelerating. FlowerStorm adopted KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.

At the same time, target surfaces are expanding: Datadog documented an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of MFA downgrade in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.

ClickFix as a service

ClickFix has also continued to industrialize. Sekoia documented the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers mapped approximately 3,000 live ClickFix payloads being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.

The technique has also expanded cross-platform, with Unit 42 documenting macOS ClickFix variants that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over 700 Ghost CMS sites were compromised to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.

Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: BlueNoroff targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and Famous Chollima embedding ClickFix in multi-stage fake job interviews.

Vishing as a payload delivery mechanism

Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.

When Push researchers infiltrated the phishing panels linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.

The financial scale is now quantifiable: Luna Moth (Silent Ransom Group), a Russia-linked Conti spinoff operating independently of the Com, has extracted up to $48 million from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the FBI issuing a dedicated flash alert.

The infrastructure behind these campaigns is industrializing independently. Okta obtained access to Work Panel, a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately documented a dedicated Teams-vishing initial access broker operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.

OAuth supply chain attacks

The OAuth supply chain dimension has also continued to produce confirmed victims. The Salesloft/Drift supply chain attack in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.

In 2026, the Anodot compromise cascaded through to Vimeo, Rockstar Games, and Zara. The Context.ai → Vercel breach followed the same structural pattern. And the Klue/Icarus breach in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.


AI is a force multiplier for attackers

Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.

The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits.

You can see more examples of these kits under the hood in our blog post infiltrating a criminal phishing panel.

Verbose phishing kit comments (a clear sign of AI involvement).
Verbose phishing kit comments (a clear sign of AI involvement).

Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability.

  • The first major device code phishing kit identified in the wild, EvilTokens, heavily used Railway, a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes.

  • Kali365's E2 edition includes an AI-powered BEC module that uses Claude Sonnet to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.

  • Rapid7's analysis of an exposed server containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.

  • Three independent operators were found running kits from public GitHub forks with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain.

  • The tooling itself is starting to embed AI as a product feature — Dolphin X, a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.

AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a malicious Claude.ai Artifact impersonating a download portal drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the LLMShare attack pattern we documented in May. A second campaign, MacSync, used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.

But the core techniques aren't changing

AI compresses the bottom layers of the Pyramid of Pain (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.

A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.


What this means for defenders

Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.

  • For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.

  • For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.

  • For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.

  • For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.

As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.


Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.

Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.

Book a live demo to learn more.

About the author
Dan Green
Dan Green
Threat Research