Hey hackers - a phishing kit in 2026 is a reverse proxy wearing the target's own login page, and the product it sells is not your password. It is the session cookie that walks past multi-factor after you finished typing the code.
The 2026 phishing kit market runs on that one shift: identity moved from the credential to the browser session, and every serious kit on sale now is built to harvest the session instead of the secret. This piece walks the ladder - what the kits are, what BigBear 2.0 changed, what buyers actually pay, and where each product leaks.
TL;DR: AiTM kits proxy the real login in real time, capture the post-authentication cookie, and replay it from a clean browser. Tycoon 2FA holds roughly 76 percent of the observed market at 120 dollars per ten days, EvilProxy sits at 150, and BigBear 2.0 - the Evilginx2 rebrand documented by CloudSEK in September 2026 - logged 5,137 captured records across 461 organizations in forty countries, 474 of them MFA-bypassed outright.
Defenders answered with token protection and device-bound sessions, which moves the fight to whether your delivery channel can land the target on the proxy at all - the same gap that makes OTP bypass work when the code is the only wall left.
What the operator collects at the far end is the session cookie - the artifact the identity provider issued after every check passed. MITRE files the pattern as access using alternate authentication (T1557.001), steal web session cookie (T1539), and web session cookie as the alternate credential (T1550.004). The login page the target trusted did its job perfectly. The failure is that trust was bound to the session, not to the machine that earned it.
Replay finishes the job. The captured cookie is loaded into a browser from a host that looks nothing like the victim - clean fingerprint, plausible geolocation, no extension residue - and the application sees a legitimate signed-in session. No password change stops it, no pushed approval fires again, and the account is open until someone expires the token or notices the session list.
The intake numbers give the scale. Across the campaign CloudSEK reconstructed 5,137 captured records: 4,148 session cookies, 1,032 sets of plaintext credentials from targets who typed them into the proxied page, and 474 captures where multi-factor was present and the cookie came out anyway. Those records spanned 3,331 source IPs, 461 victim organizations and more than forty countries, with cookies making up about 80 percent of everything taken. The average target did not fail a check. The check simply did not bind to them.
Infrastructure followed the usual pattern with better hygiene than most. The operation started on 42 VPS hosts; after the July attention, 26 were already retired, with the survivors spread across providers like Vultr and The Constant Company. Certificates came from Let's Encrypt over HTTP-01 wildcard issuance, the economics of which - free, automated, renewable - is why hostname trust stopped being a signal years ago. Exfiltration ran through Telegram channels, and harvested cookies were handled through an internal API at the path /api/jobs.
Each capture carries an x-evg-token header tying it back to the campaign, and refresh tokens with a ninety-day life mean a good capture outlives the password rotation that follows it.
That last part is what turned a phishing kit into a platform business. A cookie that lives ninety days can be resold, rented, or replayed by a buyer who never touches the lures. The /api/jobs endpoint is not a feature for the victim's benefit - it is inventory management. Every serious kit now ships some version of this: session storage, reuse tooling, and a way to hand a warm session to a second operator without exposing the panel.
The platform vendors answered on the session layer instead of the challenge layer: Microsoft's Token Protection and device-bound session tokens tie the artifact to a device key, so a cookie replayed from clean hardware presents a session that cannot finish its handshake.
FIDO2 and passkeys remove the shared secret entirely, and conditional access in Entra can require a compliant device for anything sensitive. Meanwhile the same kits get rented by state crews - the Storm-0485 and Star Blizzard clusters ran AiTM against the same calendar as everyone else - and account takeover chains keep combining them with SIM swap paths for targets whose carrier is the softer door.
EvilProxy charges a premium at 150 per ten days with monthly runs at 400 to 600, and the middle tier - Sneaky 2FA, Mamba, Whisper, FlowerStorm, SessionShark running on Cloudflare Workers - fills in at whatever the affiliate can afford.
Below the paid tier sits Evilginx, still free, still open source, still the way most operators learn the reverse-proxy pattern before they ever pay for a panel.
Lexfo's July 2026 disclosure of three fresh kits in one month shows how fast new names appear on top of that foundation, and every rental listing reads the same: supported providers, updated phishlets, uptime, refund policy. The buyer of a phishing kit in this market is often someone with a list and a budget rather than a developer, which is why support and uptime sell harder than features.
Session artifacts leak through impossible-travel alerts when the replay host geolocation disagrees with the victim's history, through the account's own session list where the new device sits plainly, and through token families that die the moment a defender revokes the whole set instead of the password.
Operator-side opsec ends more of these than any detection rule. An alias like General Boss re-used across forum posts, a Telegram channel tied to infrastructure that ends up in a writeup, wildcard certificates issued over HTTP-01 to hosts that later appear in a sinkhole - each one is a seam the market research follows.
Free kits leak hardest because their detection material is public: when anyone can download the same source a defender does, the only variable left is how differently you configured it, and configuration is where operators get lazy first.
Both sides are racing the same clock. Vendors chase phishlet freshness against provider updates; defenders chase token binding against rental panels that adapt within a week of any release. The teams that keep their position are the ones reading the change logs on both ends - the identity provider's and the kit vendor's - and moving the hour either lands. Load the session, check where it came from, and know which side of that race you are standing on before the next lure goes out.
The 2026 phishing kit market runs on that one shift: identity moved from the credential to the browser session, and every serious kit on sale now is built to harvest the session instead of the secret. This piece walks the ladder - what the kits are, what BigBear 2.0 changed, what buyers actually pay, and where each product leaks.
TL;DR: AiTM kits proxy the real login in real time, capture the post-authentication cookie, and replay it from a clean browser. Tycoon 2FA holds roughly 76 percent of the observed market at 120 dollars per ten days, EvilProxy sits at 150, and BigBear 2.0 - the Evilginx2 rebrand documented by CloudSEK in September 2026 - logged 5,137 captured records across 461 organizations in forty countries, 474 of them MFA-bypassed outright.
Defenders answered with token protection and device-bound sessions, which moves the fight to whether your delivery channel can land the target on the proxy at all - the same gap that makes OTP bypass work when the code is the only wall left.
What an AiTM kit actually is
Strip the branding and every kit in this class is the same machine: a reverse proxy sitting between the target and the provider's real authentication endpoint. The victim loads what looks like their corporate login, types the password, gets prompted for a second factor, types the code, and is forwarded through to the real service. Nothing is spoofed. The TLS certificate belongs to the real domain because the proxy terminates on infrastructure that presents it. The page is the real page. The only thing that changed is who is holding the tape.What the operator collects at the far end is the session cookie - the artifact the identity provider issued after every check passed. MITRE files the pattern as access using alternate authentication (T1557.001), steal web session cookie (T1539), and web session cookie as the alternate credential (T1550.004). The login page the target trusted did its job perfectly. The failure is that trust was bound to the session, not to the machine that earned it.
Replay finishes the job. The captured cookie is loaded into a browser from a host that looks nothing like the victim - clean fingerprint, plausible geolocation, no extension residue - and the application sees a legitimate signed-in session. No password change stops it, no pushed approval fires again, and the account is open until someone expires the token or notices the session list.
The 2026 kit ladder
Prices and market shares below come from the recurring vendor-monitoring writeups of the last year: Tycoon 2FA still leads by volume, EvilProxy undercuts on longevity, and the free tier - Evilginx itself, unchanged and open source - keeps a floor under the whole market that no paid kit can argue with.| Kit | Price | Observed share | Signature |
|---|---|---|---|
| Tycoon 2FA | 120 per 10 days, 350 per month | about 76 percent of tracked campaigns | phishlet rotation, panel-as-a-service rentals |
| EvilProxy | 150 per 10 days, 400-600 per month | second tier, strong in brokered access | long sessions, mobile-targeted lures |
| BigBear 2.0 | private, affiliate-run | five documented affiliates | Evilginx2 base, Microsoft-only offy phishlet |
| Sneaky 2FA, Mamba, Whisper | 100-300 per month range | fragmented middle tier | reverse-proxy variants with rent-a-panel models |
| Evilginx (open source) | free | the floor and the talent feeder | self-hosted, no support, full source |
BigBear 2.0, taken apart
The best-documented product of the year is BigBear 2.0, which CloudSEK published on September 7, 2026. The phishing kit is a rebrand of Evilginx2 run by an operator using the alias General Boss, staffed by five affiliates, with a single Microsoft 365 and Entra ID target profile - one phishlet they call offy, aimed at the largest identity deployment on earth and nothing else. Specialization is the tell: the operator stopped supporting everything so the one thing they support keeps working.The intake numbers give the scale. Across the campaign CloudSEK reconstructed 5,137 captured records: 4,148 session cookies, 1,032 sets of plaintext credentials from targets who typed them into the proxied page, and 474 captures where multi-factor was present and the cookie came out anyway. Those records spanned 3,331 source IPs, 461 victim organizations and more than forty countries, with cookies making up about 80 percent of everything taken. The average target did not fail a check. The check simply did not bind to them.
Infrastructure followed the usual pattern with better hygiene than most. The operation started on 42 VPS hosts; after the July attention, 26 were already retired, with the survivors spread across providers like Vultr and The Constant Company. Certificates came from Let's Encrypt over HTTP-01 wildcard issuance, the economics of which - free, automated, renewable - is why hostname trust stopped being a signal years ago. Exfiltration ran through Telegram channels, and harvested cookies were handled through an internal API at the path /api/jobs.
What the proxy does between the logins
The gap between password and inbox is where the craft lives. BigBear's phishing kit proxy checks Keep Me Signed In automatically, strips or degrades WebAuthn and FIDO2 challenges in the injected page so the target never sees a passkey prompt the operator cannot answer, and routes outbound requests through residential proxies matched to the victim's geography so the session does not hop countries mid-flow.Each capture carries an x-evg-token header tying it back to the campaign, and refresh tokens with a ninety-day life mean a good capture outlives the password rotation that follows it.
That last part is what turned a phishing kit into a platform business. A cookie that lives ninety days can be resold, rented, or replayed by a buyer who never touches the lures. The /api/jobs endpoint is not a feature for the victim's benefit - it is inventory management. Every serious kit now ships some version of this: session storage, reuse tooling, and a way to hand a warm session to a second operator without exposing the panel.
Why the code stopped being the wall
Multi-factor authentication was designed to survive a stolen password, and against credential replay it still does. The kit never needs the code's secret - it needs one live approval forwarded in real time, which a human provides while standing in what they believe is their own login screen. The 474 MFA-bypassed captures in the BigBear dataset are not a cryptographic break. They are people completing a flow they were socially engineered into, once, on a page that was byte-for-byte real.The platform vendors answered on the session layer instead of the challenge layer: Microsoft's Token Protection and device-bound session tokens tie the artifact to a device key, so a cookie replayed from clean hardware presents a session that cannot finish its handshake.
FIDO2 and passkeys remove the shared secret entirely, and conditional access in Entra can require a compliant device for anything sensitive. Meanwhile the same kits get rented by state crews - the Storm-0485 and Star Blizzard clusters ran AiTM against the same calendar as everyone else - and account takeover chains keep combining them with SIM swap paths for targets whose carrier is the softer door.
What buyers are actually paying for
The 2026 phishing kit rental market prices access to a working panel, not software. Tycoon 2FA set the standard at 120 dollars for ten days or 350 a month, and that structure stuck because ten days is the natural window of a campaign: lures land, sessions harvest, the buyer is gone before the first phishlet breaks.EvilProxy charges a premium at 150 per ten days with monthly runs at 400 to 600, and the middle tier - Sneaky 2FA, Mamba, Whisper, FlowerStorm, SessionShark running on Cloudflare Workers - fills in at whatever the affiliate can afford.
Below the paid tier sits Evilginx, still free, still open source, still the way most operators learn the reverse-proxy pattern before they ever pay for a panel.
Lexfo's July 2026 disclosure of three fresh kits in one month shows how fast new names appear on top of that foundation, and every rental listing reads the same: supported providers, updated phishlets, uptime, refund policy. The buyer of a phishing kit in this market is often someone with a list and a budget rather than a developer, which is why support and uptime sell harder than features.
| Term | Typical price | What it includes | Who it suits |
|---|---|---|---|
| 10-day rental | 120 to 150 | panel access, current phishlets, ticket support | single campaign, list already in hand |
| Monthly panel | 350 to 600 | same plus longer phishlet life and priority fixes | ongoing operation with repeat delivery |
| Affiliate run | rev share per capture | panel, lures, sometimes the proxy pool | traffic owners who would rather not touch config |
| Open source floor | free | full source, no support, your own hosting | learning, custom builds, and every defender writing signatures |
Where the model leaks
Every phishing kit in this class fails in the same places, and knowing them is worth more than knowing feature lists. Phishlet drift breaks when the provider changes login markup and the proxy starts returning a page the operator never tested, which is the natural death of any rental whose vendor has stopped pushing updates.Session artifacts leak through impossible-travel alerts when the replay host geolocation disagrees with the victim's history, through the account's own session list where the new device sits plainly, and through token families that die the moment a defender revokes the whole set instead of the password.
Operator-side opsec ends more of these than any detection rule. An alias like General Boss re-used across forum posts, a Telegram channel tied to infrastructure that ends up in a writeup, wildcard certificates issued over HTTP-01 to hosts that later appear in a sinkhole - each one is a seam the market research follows.
Free kits leak hardest because their detection material is public: when anyone can download the same source a defender does, the only variable left is how differently you configured it, and configuration is where operators get lazy first.
FRESHNESS: open the demo and walk a login against the current provider UI - phishlet drift shows up immediately as a broken redirect or a dead second-factor step. REPLAY: capture a session from the panel and load it from a second machine before believing the storage works. PROXY: ask which exit type the pool uses, because datacenter IPs turn a clean capture into an impossible-travel flag within minutes.
REFUNDS: written policy on the vendor's own panel, not a Telegram promise from a reseller. SUPPORT: does the ticket history show phishlet fixes after provider updates, or only sales replies. EXPOSURE: who else shares your panel host - a shared subdomain means the neighbor's campaign can burn the domain you are delivering from.
REFUNDS: written policy on the vendor's own panel, not a Telegram promise from a reseller. SUPPORT: does the ticket history show phishlet fixes after provider updates, or only sales replies. EXPOSURE: who else shares your panel host - a shared subdomain means the neighbor's campaign can burn the domain you are delivering from.
The stance that holds
The credential is the session now, and everything follows from accepting that. On the operator side, a phishing kit earns its price from capture quality and replay reliability - the lures, the panel skin and the feature list are packaging around a ninety-day cookie and the infrastructure that keeps it fresh. On the defender side, the challenge prompt is no longer where the fight happens: bind sessions to devices, expire token families on password change, and treat every new session list entry as an event worth a look.Both sides are racing the same clock. Vendors chase phishlet freshness against provider updates; defenders chase token binding against rental panels that adapt within a week of any release. The teams that keep their position are the ones reading the change logs on both ends - the identity provider's and the kit vendor's - and moving the hour either lands. Load the session, check where it came from, and know which side of that race you are standing on before the next lure goes out.