securityonline.info 8/10/2026, 8:01:40 AM · external

HoneyStorm's PhaaS Kit Spreads on Telegram, Steals M365 Tokens

HoneyStorm's PhaaS Kit Spreads on Telegram, Steals M365 Tokens
CyberSIXT Evidence Panel
Primary Source zerobec.com
Threat Actor
HoneyStorm

THE Greatness PhaaS platform, operated by the HoneyStorm group, is a phishing-as-a-service kit sold on Telegram that targets Microsoft 365, iCloud, Yahoo, and Google Workspace accounts. It facilitates real-time token theft and device code phishing, bypassing common email security checks through domain whitelisting. Researchers observed over 50 campaigns since April 2026, with the platform offering tools for low-skill users to launch phishing attacks using pre-made templates.

The kit can capture multi-factor authentication tokens and has been linked to specific incidents where attackers exploited safe sender lists to ensure email delivery despite failed security checks. Defense strategies include revoking not just passwords but also active tokens and re-evaluating email trust settings.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline