Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Threat Intelligence reported on March 13, 2023, that it had observed several campaigns using the DEV-1101 phishing kit send millions of phishing emails per day. The finding describes campaigns Microsoft saw at that time—not a universal or current daily rate. The report also explains why these attacks can put accounts at risk even when victims complete multifactor authentication (MFA): an adversary-in-the-middle proxy can capture the authenticated session cookie.

What Microsoft reported about DEV-1101

Microsoft described DEV-1101 as an actor that developed, supported, and advertised adversary-in-the-middle (AiTM) phishing kits. The kits included an open-source option offered since 2022, with features that automated parts of setting up and running phishing activity. Microsoft’s March 2023 report said campaigns by different actors using the kit generated millions of phishing emails per day. It identified DEV-0928, tracked since September 2022, as a prominent customer and said one observed DEV-0928 campaign involved over one million emails. Those figures are Microsoft observations from the report’s period; they do not mean every customer sent that volume daily. Microsoft Threat Intelligence’s DEV-1101 analysis describes the campaigns and tooling.

How a phishing kit scales activity

A kit can package capabilities that would otherwise require an operator to build or configure separately. Microsoft described mobile campaign management, reverse-proxy capability, CAPTCHA pages, antibot behavior, and prepared pages imitating services such as Microsoft Office and Outlook. These features can lower the setup burden and let different actors run phishing campaigns using the same underlying tooling. They help explain how activity can scale; they do not establish that every kit customer used every feature or sent millions of messages.

In an April 2023 update, Microsoft said it tracked DEV-1101 as Storm-1101. The names refer to the actor in Microsoft’s tracking; the report’s volume figures remain tied to the campaigns observed in 2023.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How an AiTM phishing attack can get around MFA

MFA is still valuable, but an AiTM attack targets the authenticated session rather than trying only to defeat the sign-in challenge. In Microsoft’s campaign example, a document-themed email linked to a purported PDF. Depending on the campaign and defenses encountered, the link could lead through an antibot redirect or CAPTCHA before reaching a page impersonating a Microsoft sign-in portal.

  1. The victim follows the link. The message directs the recipient toward a convincing, attacker-controlled sign-in page.
  2. The proxy relays authentication. The phishing site sits between the victim and the genuine service, forwarding the real sign-in flow. Credentials entered by the victim can be collected by the attacker.
  3. The victim completes MFA. If the service requests an MFA challenge, the proxy can relay it to the real service, allowing the victim to authenticate normally.
  4. The attacker captures the session. After successful authentication, the proxy can capture the resulting session cookie. An attacker may replay that cookie to access the account without completing the MFA challenge again.

This is a specific weakness of relayed sign-in flows and stolen sessions, not proof that MFA is ineffective overall. It means organizations need to protect and monitor authenticated sessions as well as credentials and sign-in challenges.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What organizations can do to reduce risk

Microsoft recommends keeping MFA in place and layering it with controls that reduce phishing exposure, strengthen identity decisions, and help detect suspicious access. Its recommendations are guidance from Microsoft, not a guarantee that any single product or control blocks every attack.

Reduce delivery and exposure

  • Use email and web protections to inspect suspicious messages and the sites users visit, and to reduce the chance that phishing links reach or deceive recipients.
  • Provide anti-phishing education that helps employees recognize unexpected document links and sign-in prompts, while recognizing that convincing pages can still fool users.

Strengthen authentication and access decisions

  • Use security defaults or conditional access policies to apply identity protections. Where available, base decisions on sign-in and device risk rather than relying on a password or MFA prompt alone.
  • Microsoft lists Microsoft Authenticator, FIDO2 security keys, and certificate-based authentication as MFA options for Microsoft customers. A FIDO2 key must be compatible with the organization’s identity provider and the user’s devices.
  • Use continuous access evaluation where supported so access decisions can respond to relevant changes during a session.

Monitor and investigate sessions

  • Watch for anomalous sign-ins, including unusual locations, internet service providers, user agents, or use of anonymizers.
  • Investigate promptly when credentials or an authenticated session may have been exposed. Review suspicious account activity and respond through the organization’s identity incident process; a successful MFA challenge does not rule out later session-cookie misuse.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep the 2023 finding separate from later phishing reports

Later Microsoft reporting describes other threats and should not be read as updated DEV-1101 counts. On March 4, 2026, Microsoft reported on Tycoon2FA, a separate AiTM phishing-as-a-service platform. Microsoft said Tycoon2FA campaigns reached over 500,000 organizations each month, and reported that by mid-2025 the service accounted for approximately 62 percent of phishing attempts Microsoft blocked. These figures concern Tycoon2FA and their stated periods, not DEV-1101. See Microsoft’s Tycoon2FA disruption announcement and its related Tycoon2FA reporting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Separately, Microsoft Threat Intelligence recorded approximately 8.3 billion email-based phishing threats detected during Q1 2026 (January through March). This is a Microsoft telemetry detection count, not a count of unique people or confirmed successful account compromises. Microsoft’s Q1 2026 email threat report provides that period-specific figure.

Rank #4
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.