Visualização de leitura
Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones
Bluekit Phishing Kit Uses Browser-in-the-Middle Attacks to Evade Detection
Google Sues Operators of AI-Powered ‘Outsider’ Phishing Kit Linked to 1.5 Million URLs

Google Alleges the Outsider AI Phishing Kit Enabled AI-Powered Cybercrime
In its lawsuit, Google claims that the operation of the Outsider AI phishing kit has facilitated large-scale cybercrime by giving bad actors access to tools that simplify the creation of phishing campaigns. The company alleges that the AI phishing kit can imitate legitimate websites while offering step-by-step instructions that help users generate convincing phishing pages through AI-assisted processes. The lawsuit places particular emphasis on alleged Gemini misuse, arguing that Google's AI tools were exploited to support phishing activities. According to Google, the developers behind Outsider used AI technologies in ways that violate the company's policies and contribute to online fraud. Google also alleges that the individuals responsible for the Outsider AI phishing kit are anonymous cybercriminals based in China. The company claims these actors abused services such as Google Cloud and Google Drive while also misusing Google's trademarks to create a false sense of legitimacy around their operations.More Than 1.5 Million URLs Linked to the AI Phishing Kit
The scale of the alleged operation is one of the most significant aspects of the lawsuit. Google reported that it identified more than 1.5 million URLs associated with the Outsider AI phishing kit between November and April. The large number of detected URLs suggests that the phishing infrastructure was extensive and capable of reaching a substantial number of potential victims. Google's findings highlight how rapidly phishing operations can expand when aided by automation and AI-driven tools. As concerns about Gemini misuse and AI-enabled cybercrime continue to grow, security experts have warned that phishing attacks are becoming increasingly difficult for users to distinguish from legitimate communications.Google Partners With FBI and Telecom Providers
Google says it is taking a coordinated approach to disrupt the Outsider network. In a blog post, Google General Counsel Halimah DeLaine Prado stated that the company is working alongside the Federal Bureau of Investigation (FBI) as well as major telecommunications companies including AT&T, T-Mobile, and Verizon. According to DeLaine Prado, the collaboration aims to dismantle the infrastructure supporting the Outsider AI phishing kit. The effort combines legal action, industry cooperation, and technical measures to address what Google views as an evolving cybersecurity threat. The partnership reflects a broader trend within the technology and telecommunications sectors, where organizations are joining forces to combat sophisticated phishing operations and online fraud schemes.Rising Concerns Over Gemini Misuse and AI-Driven Scams
The lawsuit also draws attention to wider concerns across the cybersecurity industry about the misuse of artificial intelligence. Experts have warned that AI tools can help criminals create more persuasive messages, realistic websites, and effective social engineering campaigns. Commenting on the issue, Brett Leatherman, Assistant Director of the FBI's Cyber Division, said that criminals are increasingly turning to AI to make fraudulent activity more convincing and more difficult to detect. Leatherman emphasized the importance of public-private partnerships in disrupting cybercriminal operations, pointing to collaborations such as the one between Google and the FBI as a key component in combating modern digital threats. The allegations surrounding Gemini misuse serve as another example of how AI technologies, while beneficial in many legitimate applications, can also be exploited by malicious actors seeking to improve the effectiveness of phishing attacks.Legislative Efforts to Combat AI-Powered Fraud
Beyond its lawsuit against Outsider, Google is also advocating for policy measures aimed at reducing online scams. DeLaine Prado noted that the company supports seven bills currently pending in the U.S. Congress that are intended to address scamming activities. Google's backing of the proposed legislation signals a broader effort to combine legal, technological, and policy-based responses to the rise of AI-enabled cybercrime. The company argues that tackling threats such as the Outsider AI phishing kit requires cooperation across government agencies, technology providers, law enforcement organizations, and lawmakers. As AI tools continue to evolve, the lawsuit against Outsider highlights the growing challenge facing the cybersecurity sector. The case not only focuses on the alleged abuse of Google's services and trademarks but also raises larger questions about preventing Gemini misuse and limiting the role of AI in sophisticated phishing campaigns.FBI Flags Kali365 as New Phishing Threat Targeting Microsoft 365 Users

How the Kali365 Phishing Kit Works
The FBI explained that the platform relies on a deceptive but technically simple attack chain designed to exploit user trust. The process typically begins with a phishing email impersonating trusted productivity or document-sharing services. The email contains a device authentication code and instructions asking the victim to visit a legitimate Microsoft verification page. Because the webpage itself is genuine, many users assume the request is safe. Once the targeted user enters the provided code, they unknowingly authorize the attacker’s device to access their Microsoft 365 account. The attacker then captures OAuth access and refresh tokens, enabling persistent access without requiring the victim’s password or additional MFA verification. This technique is particularly dangerous because it does not rely on traditional credential theft. Instead, it abuses Microsoft’s authentication framework to gain legitimate session access. The FBI noted that after successful token capture, attackers can continue accessing services such as Outlook email accounts, Teams communications, and OneDrive files without triggering additional login prompts.Why OAuth Token Theft Is Becoming a Growing Threat
Security researchers say OAuth token theft is becoming increasingly popular among cybercriminals because it allows attackers to bypass many traditional security controls. Unlike passwords, OAuth tokens are designed to maintain authenticated sessions across services. If stolen, they can provide attackers with ongoing access until revoked or expired. The FBI warned that Kali365 significantly lowers the barrier to entry for cybercrime operations by offering built-in phishing templates, AI-generated phishing lures, automated campaign tools, and real-time dashboards that track victims and stolen tokens. This means attackers no longer need advanced technical expertise to launch phishing campaigns against businesses using Microsoft 365 environments. The platform’s availability on Telegram also makes it easier for threat actors to distribute and monetize phishing infrastructure at scale.FBI Shares Protection Measures Against Kali365 Attacks
To reduce exposure to these attacks, the FBI advised organizations to restrict or block device code authentication flows wherever possible. One of the key recommendations includes implementing conditional access policies that block device code flow for most users while allowing limited exceptions for essential business operations. Organizations are also encouraged to audit existing device authentication workflows to identify legitimate dependencies before enforcing restrictions. The FBI further recommended blocking authentication transfer policies that allow authentication to move between computers and mobile devices, as these workflows can potentially be abused during phishing attacks. For organizations unable to fully disable device code flow, the agency suggested excluding emergency access accounts from restrictions to avoid accidental lockouts during critical situations.FBI Urges Victims to Report Incidents
The FBI is urging anyone impacted by the Kali365 phishing campaign to report incidents through the Internet Crime Complaint Center (IC3). Victims are encouraged to preserve and submit phishing emails, suspicious login activity, unauthorized devices, IP addresses, and active session information that could assist investigators. The agency also pointed users toward phishing mitigation guidance published by the Cybersecurity and Infrastructure Security Agency, which outlines defensive measures organizations can take to reduce phishing risks. The rise of Kali365 Phishing-as-a-Service highlights how cybercriminals are increasingly shifting toward token-based attacks that exploit trusted authentication systems instead of relying solely on password theft. As phishing platforms continue evolving, security experts warn that organizations using cloud productivity platforms like Microsoft 365 will need stronger identity protection measures and closer monitoring of authentication activity to reduce the risk of account compromise.FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Account
New AI-Powered Bluekit Phishing Kit Targets Major Platforms with MFA Bypass Attacks
Authorities Dismantle ‘W3LL’ Phishing Empire Powering Global Business Email Attacks

An international operation, coordinated between the FBI Atlanta Field Office and Indonesian law enforcement agencies has led to a taken down of a major phishing infrastructure that enabled cybercriminals worldwide to steal credentials and attempt fraud exceeding $20 million.
The crackdown targeted a cybercrime ecosystem built around the “W3LL phishing kit,” a tool designed to replicate legitimate login pages and harvest user credentials at scale. Authorities say the platform allowed attackers to compromise thousands of accounts and carry out widespread financial fraud.
More Than a Phishing Tool
Investigators describe W3LL not as a single piece of malware, but as a fully developed “phishing-as-a-service” operation. For a relatively low cost of around $500, cybercriminals could purchase access to the kit and launch highly convincing phishing campaigns with minimal technical expertise.
The service was supported by an underground marketplace known as W3LLSTORE, where stolen credentials were bought and sold. Between 2019 and 2023, more than 25,000 compromised accounts were traded through the platform.
Even after the marketplace was shut down, the operation continued through private and encrypted channels, allowing it to evolve and remain active.
Also read: New Phishing Kit ‘FishXProxy’ Aims To Be ‘Ultimate Powerful Phishing Kit’
Built for Corporate Account Takeovers
According to research by Group-IB, the W3LL ecosystem was specifically designed to target corporate environments, particularly business email systems such as Microsoft 365.
The toolkit included a range of capabilities beyond simple phishing pages, forming an end-to-end attack chain. These included tools for:
- Sending large-scale phishing emails
- Harvesting and validating email accounts
- Hosting malicious infrastructure
- Managing stolen credentials
Group-IB estimates that around 500 threat actors were actively using W3LL tools, turning the platform into a structured cybercrime network rather than a loose collection of attackers.
Bypassing Multi-Factor Authentication
One of the most dangerous aspects of the W3LL kit was its use of adversary-in-the-middle (AitM) techniques. This allowed attackers to intercept login sessions in real time, capturing not just usernames and passwords but also authentication tokens.
As a result, even accounts protected by multi-factor authentication (MFA) could be compromised, giving attackers persistent access to corporate systems.
Security researchers say this capability made W3LL particularly effective in business email compromise (BEC) attacks—one of the most financially damaging forms of cybercrime today.
Global Scale and Impact
The phishing kit was used in attacks targeting organizations across multiple industries, including finance, healthcare, manufacturing, and IT services.
Data suggests that tens of thousands of corporate accounts were targeted globally, with a significant concentration of victims in the United States, followed by Europe and Australia.
Between 2023 and 2024 alone, the infrastructure was linked to more than 17,000 phishing attempts worldwide.
Arrest and Infrastructure Seizure
As part of the operation, authorities seized domains and infrastructure used to distribute the phishing kit and facilitate credential theft. Indonesian police also detained the suspected developer behind the platform, identified only as “G.L.”
Officials say this marks a significant step in targeting not just users of cybercrime tools, but the developers who enable large-scale attacks.