Skip to content
PhaaS

Introducing Cavalier’s New Threat Feeds: Deep Dive into Phishing-as-a-Service (PhaaS) Intelligence

InfoStealers
3 min read

Introducing Cavalier’s New Threat Feeds: Deep Dive into Phishing-as-a-Service (PhaaS) Intelligence

We are thrilled to introduce three new Threat Feed modules in Cavalier: C2 Data, ClickFix, and PhaaS (Phishing-as-a-service). Together, they give security teams comprehensive visibility into active attacker infrastructure – from infostealer command-and-control (C2) servers to malicious ClickFix pages executing clipboard injection, to turnkey Phishing-as-a-service (PhaaS) kits targeting corporate credentials.

Overview of the Threat Feeds monitoring options
Overview of the new Threat Feeds monitoring options available inside Cavalier, including the dedicated PhaaS Feed.

What’s New: PhaaS Intelligence

As Phishing-as-a-Service (PhaaS) platforms become extremely prominent in high-profile corporate hacks, giving lower-tier actors turnkey access to advanced credential harvesting tools, preemptive visibility is more critical than ever. The new PhaaS Threat Feed is unique to Hudson Rock, providing an unparalleled view into active phishing host networks before they are deployed in targeted spear-phishing campaigns against your workforce.

Overview of the PhaaS feed in Cavalier
A high-level overview of the Phishing-as-a-Service (PhaaS) intelligence feed within Cavalier, enabling security teams to monitor active phishing host networks and operational statuses.

Inside Cavalier, security teams can seamlessly review:

  • Active phishing host networks and root domains
  • Specific kit tags and deployment platforms
  • Resolved IP nodes and server infrastructure
  • Infostealer credential telemetry linked to the hosting platform

Tracking the Most Dangerous Phishing Kits

Cavalier groups PhaaS hosts by their specific operational kits, allowing defenders to understand the exact tactics they are facing. Our intelligence tracks massive networks running well-known platforms like Eviltokens and Kali365, as well as exclusive, recently uncovered campaigns like SessionSerpent—intelligence you will only find surfaced through Hudson Rock.

Examples of PhaaS infrastructure kits
Detailed grouping of PhaaS hosts by kit, featuring prominent platforms like Kali365, Eviltokens, Generic PhaaS, and the recently uncovered SessionSerpent campaign, tracked exclusively by Hudson Rock.

Uncovering Infrastructure and Initial Access

The PhaaS feed allows you to go beyond the domain level and map out the entire operational footprint of an attacker. For example, you can surface surface infrastructure like garage-door-repair(.)cyou running Eviltokens, or pinpoint specific IP nodes like 43.172.6.35 tied to Kali365 operations.

Infrastructure servers and resolved IPs
Deep dive into an active PhaaS campaign, showing the underlying infrastructure servers, ASNs, and resolved IPs utilized by the threat actors to host their credential harvesting kits.

Crucially, just like our ClickFix and C2 modules, the PhaaS feed integrates directly with our infostealer telemetry. This allows you to instantly see if a host domain (e.g., webcindario(.)com) has compromised employee credentials tied to it, revealing exactly how attackers gained initial control of the server to host their phishing infrastructure.

Seamless API Integration for Proactive Defense

By feeding these surfaced domains, IP networks, and hosting infrastructure directly into your perimeter controls, firewalls, and DNS sinks, organizations can preemptively block turnkey phishing networks before employees receive a single malicious email.

All datasets are fully accessible via REST API endpoints for automated ingestion into your SIEM or SOAR. Teams can utilize the GET /json/v3/threat-feeds/phaas endpoint to retrieve active Phishing-as-a-Service indicators with flexible filtering, or use the GET /json/v3/threat-feeds/phaas/{host} endpoint for specific host network lookups and operational status checks.

Protect Your Organization from Imminent Intrusions

With our new Threat Feeds, cybersecurity teams can monitor live C2 infrastructure from infostealer campaigns, ClickFix networks, and PhaaS operations to proactively block malicious communications.

To learn more about how Hudson Rock protects companies from intrusions caused by info-stealer infections of employees, partners, and users, and how we enrich existing cybersecurity solutions with our cybercrime intelligence API, please schedule a call with us, here:
https://www.hudsonrock.com/schedule-demo

We also provide access to various free cybercrime intelligence tools that you can find here:
www.hudsonrock.com/free-tools

Thanks for reading, Rock Hudson Rock!
Follow us on LinkedIn: https://www.linkedin.com/company/hudson-rock
Follow us on Twitter: https://www.twitter.com/RockHudsonRock

Tags PhaaS
Free Tools Check your exposure