LevelBlue + SentinelOne Partner to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

30 Minute Watch Karla Agregado,
Security Researcher, LevelBlue

Phishing has gotten harder to catch.

Attackers are no longer relying on obvious fake pages. They are routing campaigns through legitimate domains, trusted cloud services, and sophisticated phishing kits designed to bypass detection at every layer.

In this 30-minute technical session, LevelBlue SpiderLabs researcher Karla Agregado breaks down a pattern she has been tracking across recent phishing campaigns: the convergence of compromised domains, abused cloud services, and advanced phishing kits like Tycoon 2FA working together to obscure the true destination from users and security tools alike.

In this session, you'll learn:

  • How attackers abuse legitimate domains, cloud services, and CAPTCHA tools as redirection layers
  • How compromised domains provide cover inside active phishing campaigns
  • How Tycoon 2FA kits work and why their use is growing
  • The full attack chain from initial arrival to final phishing URL
  • The indicators that reveal what automated tools often miss.

Watch the Webinar

Related Resources

Current: resourceswebinarsmulti-hop-phishing-kits-clouds-and-chained-attacks
Resource: resourceswebinarsdiscover-how-security-leaders-maximize-microsoft-security
Webinar

Discover How Security Leaders Maximize Microsoft Security

Current: resourceswebinarsmulti-hop-phishing-kits-clouds-and-chained-attacks
Resource: resourceswebinarsai-alignment-and-risk-insights-from-levelblues-cto-research
Webinar

AI, Alignment, and Risk: Insights from LevelBlue's CTO Research

Current: resourceswebinarsmulti-hop-phishing-kits-clouds-and-chained-attacks
Resource: resourceswebinarslevelblue-ttp-briefing-q1-2026-trust-abuse-exposes-weaknesses
Webinar

LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses