



Phishing has always been the threat actor’s weapon of choice — cheap to launch, effective at scale, and devastatingly difficult for end users to resist. But the threat has matured dramatically. What once required technical skill to mount is now available to virtually anyone with a cryptocurrency wallet and a grudge. Welcome to the age of Phishing-as-a-Service (PhaaS): industrialised credential-harvesting kits sold on dark-web marketplaces, complete with real-time dashboards, 24/7 support, and MFA-bypass technology built in.
For Indian enterprises — navigating DPDP Act obligations, CERT-In’s 6-hour breach reporting directive, and rapidly expanding digital footprints — PhaaS represents a strategic escalation. This guide explains how these platforms work, why traditional email gateways are no longer enough, and the layered defence architecture that PJ Networks deploys for clients across manufacturing, BFSI, healthcare, and retail sectors.
PhaaS platforms are subscription or pay-per-use services that package every element a phishing campaign needs into a single, polished offering. A threat actor — even one with minimal technical ability — can rent a fully configured kit that includes:
Well-documented PhaaS frameworks — including Evilginx, Modlishka, and commercial successors that build on their techniques — have been used in publicly reported incidents targeting Microsoft 365 environments, banking portals, and government contractor supply chains. The MITRE ATT&CK framework catalogues these techniques under T1566 (Phishing), T1111 (Multi-Factor Authentication Interception), and T1539 (Steal Web Session Cookie).
India’s digital transformation over the past five years has dramatically widened the attack surface that PhaaS operators exploit:
“The barrier to entry for a sophisticated phishing campaign is now lower than the monthly salary of the analyst your organisation assigned to defend against it. That asymmetry is the defining challenge of the PhaaS era.”
Many organisations still rely on a Secure Email Gateway (SEG) as their primary phishing defence. PhaaS kits are engineered specifically to circumvent these controls:
PhaaS infrastructure rotates sending domains and IPs on a schedule designed to stay ahead of reputation blacklists. A domain may be less than 48 hours old when it delivers a campaign — pristine reputation, zero DMARC violation. By the time feeds catch up, the campaign is over.
Lure pages are frequently hosted on Microsoft Azure, Amazon AWS, or Google Cloud Storage — domains that organisations almost never block and that carry TLS certificates from trusted CAs. URL scanners that rely on domain age or hosting provider reputation are blind to these.
Modern PhaaS kits insert three to six redirects before the victim lands on the harvesting page. Each hop may pass through a legitimate redirect service — a document-sharing platform, a regional CDN — that is trusted by email gateways. By the time the final URL is resolved, the gateway has already delivered the email.
The most dangerous evolution: the kit does not host a fake login page. Instead it proxies the real Microsoft 365 or bank login page in real time, harvesting the session cookie after successful MFA. The user completes their genuine MFA challenge — and the attacker captures a live, authenticated session. Conditional-access policies that check for compliant device registration are the only reliable technical control at this layer.
SOC teams face a structural detection gap with PhaaS campaigns. The initial delivery event looks clean. The click happens on a personal device or a BYOD endpoint that is not EDR-enrolled. The credential use occurs hours later, from a residential IP in a plausible geographic location, against a cloud service that the organisation uses every day.
The signals that do exist — impossible-travel alerts, unusual OAuth consent grants, new email-forwarding rules created within minutes of login — are present in most environments’ logs, but they are buried in volume and require correlated analysis to surface. This is precisely the detection problem that a modern SIEM with MITRE ATT&CK mapping is built to solve.
Defending against PhaaS requires connecting signals from email, identity, endpoint, and network layers — a correlation challenge that manual analyst workflows cannot meet at enterprise scale. PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd; PJ Networks is its primary field deployment and operations partner, running the platform for clients across India.
Here is how each pillar of Ora addresses the PhaaS kill chain:
Ora’s SIEM ingests logs from email gateways, Azure AD / Entra ID, FortiGate NGFW, endpoint agents, and cloud-application audit trails into a single correlation engine. Detection rules are mapped directly to MITRE ATT&CK techniques — so a T1539 (session-cookie theft) alert fires when an authenticated session appears from a new IP within minutes of a successful MFA event, not when an analyst manually pieces together three log sources the next morning. Graph-based attack storyline reconstruction lets analysts trace the full lateral-movement chain rather than triaging individual alerts in isolation.
For Indian enterprises, this directly addresses CERT-In’s direction on log retention: Ora’s tiered hot/cold/archive storage keeps event data in-country for the full 180-day retention window that CERT-In’s guidelines indicate, ensuring both rapid investigation and long-term forensic availability.
PhaaS post-exploitation often involves lateral movement: credential stuffing against internal systems, exfiltration of the Active Directory credential database, or creation of persistent OAuth access. Ora’s NMS provides unified observability across FortiGate firewalls, switches, APs, and WAN/SD-WAN links, with LLDP/CDP topology discovery and network path tracing. ML-based anomaly detection flags unusual internal traffic patterns — such as a workstation that has never before communicated with the domain controller suddenly making high-volume LDAP queries — that are characteristic of post-phishing lateral movement. This is particularly valuable in multi-vendor estates where NOC visibility is fragmented across separate management consoles.
For manufacturing, retail, and multi-site organisations, a phishing campaign that harvests facility-manager credentials can have physical consequences — door-access system compromise, CCTV blackout, or supply-chain tampering. Ora’s video surveillance (VMS) module manages ONVIF, Hikvision, and Dahua cameras alongside network security events in a single operations view. When a physical security anomaly correlates with a network security event — a badge-access failure at the same timestamp as a failed VPN login — the operations team sees both in one timeline rather than investigating two separate systems.
When a PhaaS compromise is confirmed, the response clock starts immediately. CERT-In’s 6-hour incident-reporting window is not aspirational — it is a compliance obligation, and late or incomplete reports carry formal consequences. Ora’s SOAR module provides playbook automation with pre-built connectors and automated response actions. A confirmed session-hijack alert can trigger an automated response sequence: revoke the session token in Azure AD, push a blocklist entry to the client’s FortiGate, quarantine the user’s endpoint, open a CERT-In incident record with pre-populated fields, and notify the CISO — all within minutes of detection. Automation is what makes the 6-hour timeline realistic at scale.
If PhaaS-related threats are straining your SOC’s detection and response capacity, speak with our team about how we deploy and operate Ora for clients in India.
No single control defeats PhaaS. The following layered architecture represents current best practice, based on PJ Networks’ deployment experience across Indian enterprise environments:
India’s Digital Personal Data Protection Act, 2023 (DPDP Act) introduces statutory obligations for data fiduciaries that a successful PhaaS attack can directly trigger. If compromised credentials provide access to systems that process personal data — employee records, customer databases, transactional data — the data fiduciary must:
The DPDP Act does not prescribe specific technical controls, but it does require that a data fiduciary be able to demonstrate “reasonable security safeguards.” A layered defence architecture — including FIDO2 MFA, ZTNA, NGFW with TLS inspection, and SIEM-based detection — supports compliance with this obligation and helps evidence the required due diligence. Note that no technical control alone makes an organisation “DPDP compliant” — compliance is a programme, not a product.
If you are assessing your organisation’s PhaaS exposure today, start here:
PJ Networks provides managed security services to Indian enterprises across manufacturing, BFSI, healthcare, logistics, and retail sectors. Our capabilities relevant to PhaaS defence include:
PhaaS has raised the baseline competency required to mount a sophisticated phishing attack to near zero. The organisations that stay ahead of it are those that invest in layered defences, correlated detection, and practised response — not those that rely on a single gateway product or annual security-awareness training.
To discuss a PhaaS-readiness assessment for your organisation, contact the PJ Networks team.