
- VoidProxy is a new phishing-as-a-service platform targeting Microsoft 365 and Google accounts
- Attacks begin from compromised email addresses and use fake login pages hosted on disposable domains
- Phishing kits now include automation, support, and GenAI-enhanced content, making campaigns more convincing and harder to detect
Cybercriminals are using a brand new phishing-as-a-service (PhaaS) platform called VoidProxy to steal people’s Microsoft 365 and Google accounts, including those defended by two layers of protection according to security researchers Okta, who spotted one of these campaigns recently, and described them as sophisticated and evasive.