Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

30 Minute Watch Karla Agregado,
Security Researcher, LevelBlue

Phishing has gotten harder to catch.

Attackers are no longer relying on obvious fake pages. They are routing campaigns through legitimate domains, trusted cloud services, and sophisticated phishing kits designed to bypass detection at every layer.

In this 30-minute technical session, LevelBlue SpiderLabs researcher Karla Agregado breaks down a pattern she has been tracking across recent phishing campaigns: the convergence of compromised domains, abused cloud services, and advanced phishing kits like Tycoon 2FA working together to obscure the true destination from users and security tools alike.

In this session, you'll learn:

  • How attackers abuse legitimate domains, cloud services, and CAPTCHA tools as redirection layers
  • How compromised domains provide cover inside active phishing campaigns
  • How Tycoon 2FA kits work and why their use is growing
  • The full attack chain from initial arrival to final phishing URL
  • The indicators that reveal what automated tools often miss.

Watch the Webinar

Related Resources

Current: resourceswebinarsmulti-hop-phishing-kits-clouds-and-chained-attacks
Resource: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Webinar

Inside MAD-CAT: How We Recreated the Meow Attack for Security Testing

Current: resourceswebinarsmulti-hop-phishing-kits-clouds-and-chained-attacks
Resource: resourceswebinarsinside-1500-incidents-when-trusted-tools-become-attack-vectors
Webinar

Inside 1,500+ Incidents: When Trusted Tools Become Attack Vectors

Current: resourceswebinarsmulti-hop-phishing-kits-clouds-and-chained-attacks
Resource: resourceswebinarsttp-emea-briefing-q2-2026
Webinar

LevelBlue EMEA TTP Briefing Q2 2026