Webinar Description
Key Takeaways
- Explores the latest multi-hop phishing tactics leveraging legitimate domains and cloud services
- Dissects the operation of Tycoon 2FA phishing kits and CAPTCHA-based redirection
- Breaks down the full phishing attack chain, from initial contact to final payload
- Highlights detection strategies for threats that evade automated tools
- Targets cybersecurity professionals seeking advanced threat intelligence and practical defense insights
The cybersecurity landscape continues to evolve as attackers adopt increasingly sophisticated methods to bypass traditional defenses. “Multi-Hop Phishing: Kits, Clouds, and Chained Attacks” is a focused, 45-minute technical session led by LevelBlue SpiderLabs researcher Karla Agregado. The event zeroes in on the latest phishing campaigns that exploit trusted infrastructure and advanced toolkits, challenging even the most vigilant security teams.
Understanding Multi-Hop Phishing Tactics
Phishing has become more elusive, with attackers now routing campaigns through legitimate domains and widely used cloud services. This approach not only increases the credibility of malicious messages but also complicates detection efforts. The session examines how these tactics obscure the true destination of phishing links, making it difficult for both users and automated security tools to identify threats.
Dissecting the Attack Chain
Participants will gain a detailed look at the anatomy of recent phishing campaigns. The discussion covers the use of CAPTCHA tools as redirection layers, which add another hurdle for detection systems. Special attention is given to the proliferation of Tycoon 2FA phishing kits, which are designed to bypass multi-factor authentication and further complicate incident response.
Detection and Defense Strategies
Traditional security tools often miss subtle indicators embedded within multi-layered phishing attacks. The session provides practical guidance on identifying these overlooked signals, equipping security professionals with actionable intelligence to strengthen their defenses. Attendees will leave with a clearer understanding of how to recognize and respond to advanced phishing threats that exploit legitimate infrastructure.
Industry Context and Audience
This webinar is tailored for cybersecurity professionals—researchers, analysts, SOC teams, and IT security managers—working in sectors where phishing poses a significant risk, such as finance, healthcare, and technology. The content is especially relevant for those responsible for threat detection, incident response, and organizational security strategy.
Event Format and Focus
Delivered as a virtual technical session, the event emphasizes education and thought leadership. While the primary goal is to share actionable knowledge, the session also highlights LevelBlue’s expertise in threat intelligence and advanced detection, positioning the company as a resource for organizations seeking to stay ahead of evolving phishing tactics.

