#sneaky2fa
Sneaky2FA, a popular among cybercriminals phishing-as-a-service (PhaaS) kit, has added Browser-in-the-Browser (BitB) capabilities, giving "customers" the option to launch highly deceptive attacks.
Sneaky2FA PhaaS kit now uses redteamers' Browser-in-the-Browser attack
Sneaky2FA, a popular among cybercriminals phishing-as-a-service (PhaaS) kit, has added Browser-in-the-Browser (BitB) capabilities, giving "customers" the option to launch highly deceptive attacks.
www.bleepingcomputer.com
November 19, 2025 at 10:00 PM
~Anyrun~
Phishing exposure reaches 69.9% across five US industries, increasingly targeting credentials, sessions, and tokens.
-
IOCs: Tycoon, Sneaky2FA, EvilProxy
-
#IdentityAttack #Phishing #ThreatIntel
US Industry Phishing Risk
any.run
September 23, 2026 at 4:01 PM
Sneaky2FA, a Telegram-based phishing kit, steals Microsoft 365 credentials. It uses evasion techniques & obfuscated code. Offered as Phishing-as-a-Service via compromised sites, it accepts crypto payments. Detect it via authentication logs & URL analysis.#Sneaky2FAThreat
January 20, 2025 at 3:02 PM
🔍 TDR analysts discovered a new Adversary-in-the-Middle (#AiTM) #phishing kit, specifically targeting Microsoft 365 accounts and circumventing 2-step verification: Sneaky 2FA

https://blog.sekoia.io/sneaky-2fa-exposing-a-new-aitm-phishing-as-a-service/

#detection #sneaky2fa
Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
In this blog post, learn about Sneaky 2FA, a new Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts.
blog.sekoia.io
January 16, 2025 at 4:17 PM
Researchers from Proofpoint have reported an increase in AitM activity originating from #NovaCookies, a suspected variant of the #Sneaky2FA phishing kit.
July 1, 2026 at 3:29 PM
While the original Sneaky2FA appeared to focus mainly on Microsoft accounts, the NovaCookies variant includes dedicated flows for other identity providers, including Okta, and Entra domains federated to GoDaddy.
July 1, 2026 at 3:34 PM
New BitB Phishing Threat #SOC #TechSecurity
Sneaky2FA adds Browser-in-the-Browser attacks that mimic Microsoft 365 logins.

#CyberSecurity #Phishing #BitB #MFABypass #Microsoft365 #SecurityUpdate #TechSafety #Technijian
November 20, 2025 at 11:27 AM
Sneaky2FA phishing tool adds ability to insert legit-looking URLs
Since the introduction of multi-factor authentication (MFA), threat actors have been finding ways to get around what can be an effective defense against phishing attacks. In their latest move, those behind the Sneaky2FA phishing-as-a-service (PhaaS) kit have added browser-in-the-browser (BITB) functionality to help crooks design phishing pages that fool victims. This function allows the crook to embed a browser window on the victim’s desktop containing a phishing page that includes a URL address bar that can be customized by the attacker to look like a legitimate address to, for example, Microsoft online. BITB differs from attacker-in-the-middle (AITM) attacks, where the threat actor creates an embedded browser window that contains the actual phishing page. Employees trained to look for suspicious URLs might even be fooled, because the internet address looks real. However, the pop-up window, enabled through a reverse proxy, contains an iframe pointing to a malicious server that captures credentials and MFA codes entered by the unwitting victim. Then the attacker can steal the live session of the account being targeted, as well as user credentials, by logging in in real time. ## A warning to CSOs The report this week from researchers at Push Security describing the Sneaky2FA browser-in-the-browser capability is a warning to CSOs that they have to adapt their employee security awareness training as well as their defensive technology. BITB tactics are spreading, says the report. It notes that Raccoon0365 was another PhaaS service that has utilized BITB functionality after announcing a ‘BITB mini-panel’ would be added to its offerings. In September, Cloudflare and Microsoft dismantled that gang’s IT infrastructure. BITB has been known as a concept since 2022, notes David Shipley, head of Canadian-based security awareness training firm Beauceron Security. In fact, he added, it is increasingly used by advanced red teams in penetration tests to defeat security controls like MFA. “It hasn’t been widely used because it hasn’t been needed to get the job done when it comes to compromising organizations,” he said. But as defenses improve, he’s seen use of this technique increase. What’s dangerous, he said, is that phishing-as-a-service tools are making it easier for entry-level criminals to use these more advanced techniques. “This is why I’ve always hated it when people use language like ‘phishing resistant,’ or even worse, ‘phishing proof’ solutions. Additional identity controls like MFA add more friction and resiliency, but can still be bypassed by clever attackers. That’s why it’s critical organizations have both robust technology security control as well as an aware community.” That means CSOs and infosec leaders have to do more than just annual compliance-driven security training, Shipley said, instead motivating employees to keep an eye out for unusual things in messaging so they spot and stop phishing and other cyber attacks. “That’s where many organizations are struggling,” he said. “Not in instructing people or passing on knowledge, but in creating a security culture that motivates people to apply knowledge.” **Related content: How MFA gets hacked** The addition of BITB, along with the improvement of detection evasion techniques, means that traditional security controls such as email gateways, web filters, and signature-based defenses will continue to be reliably bypassed, Push Security’s report says. ## A look at Sneaky2FA Sneaky2FA operates through a full-featured bot on Telegram, says the report. Customers reportedly receive access to a licensed, obfuscated version of the source code and deploy it independently. This means they can customize it to their needs. On the other hand, the report notes, Sneaky2FA implementations can be reliably profiled and tracked due to the codebase similarities. Sneaky2FA has been frequently seen using anti-analysis techniques to detect or disable browser developer tools so they can block attempts to analyze the page for malicious content, the report adds. Defenders should note that the HTML and JavaScript of Sneaky2FA pages are heavily obfuscated to evade static detection and pattern-matching, the report says. This includes using tactics such as breaking up UI text with invisible tags, embedding background and interface elements as encoded images instead of text, and other changes that are invisible to the user, but make it hard for scanning tools to fingerprint the page. Campaigns are also known to use a ‘burn-and-replace’ tactic, hiding behind a fresh, long, randomized URL that lies dormant or serves harmless content until right before the attack, and then quickly vanishes. This is to defeat domain reputation or pattern-matching defense technologies. ## A game of cat and mouse Dan Green, author of the Push Security report, told _CSO_ in an email that email isn’t the only way BITB attacks are spreading. In the past several months, his firm has seen LinkedIn Messenger and Google Search being used as well. “We would encourage security teams to re-evaluate how they approach phishing detection,” he said. “[Phishing] is becoming increasingly sophisticated, it’s no longer just an email problem, and the risks are significant. A compromised enterprise cloud account (for example, Microsoft or Google Workspace) is effectively the key to everything you access in the course of the modern workday. This isn’t just the direct access to your enterprise cloud suite, but the downstream application access via SSO (single sign-on) that can be hijacked by the attacker. Most breaches start with compromised identities today, compared with software exploits or malware execution.” Roger Grimes, data driven defense CISO advisor at security awareness training provider KnowBe4, noted that browser vendors have worked for decades trying to prevent malicious popup boxes from appearing because they are so tricky. However, he added, criminals keep on figuring out ways to bypass the protections. On the other hand, he added, it is getting ever harder for criminals to create malicious popup boxes. Users still have a chance to see what is happening if they are aware, he said. “Sadly,” he said, “a large percentage of users don’t.” Educating users by providing information and examples of how browser pop-up attacks work is key, he said. In addition, CSOs should make sure browsers used by employees are as well configured as they can be to prevent these types of attacks. “Browser vendors will respond and close the holes, but it’s always a reactive game of cat-and-mouse with the defenders always behind.” he said. “Pretty soon AI-enabled defense tools will do a better job at preventing them from happening at all. We just have to cover the gap for now.”
www.csoonline.com
November 21, 2025 at 4:22 AM
🚨 New Threat Alert: #Sneaky2FA PhaaS targets Microsoft 365, leveraging AiTM phishing, anti-bot features, and Telegram-based operations. Real-time credential theft + session hijacking = 🚩.

Read: hackread.com/telegram-sne...

#CyberSecurity #Phishing #Microsoft365 #Telegram #Scam
Telegram-Based "Sneaky 2FA" Phishing Kit Targets Microsoft 365 Accounts
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
January 20, 2025 at 11:49 AM
Law enforcement seized 330 Tycoon 2FA domains, cutting attacks from 9M to 2M/month. Phishers shifted to Mamba 2FA, EvilProxy, and Sneaky 2FA, adopting device code phishing methods. #Tycoon2FA #DevicePhishing #Russia
Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing
Tycoon 2FA's coordinated takedown knocked out 330 domains and sharply reduced its monthly attack volume, but the phishing ecosystem quickly adapted and dispersed. Competitors like Mamba 2FA, EvilProxy, and Sneaky 2FA have absorbed activity and attackers are increasingly adopting device code phishing techniques. #Tycoon2FA #Mamba2FA #EvilProxy #Sneaky2FA #DeviceCodePhishing
www.hendryadrian.com
April 18, 2026 at 11:45 AM
~Anyrun~
72.7% of finance investigations involve phishing; modern kits increase SOC workload.
-
IOCs: Tycoon2FA, Sneaky2FA, EvilProxy
-
#Finance #Phishing #ThreatIntel
US Finance Phishing Pressure
any.run
August 29, 2026 at 1:12 PM
«Kratos, la plataforma de phishing como servicio (PhaaS) responsable de una gran parte de los recientes robos de credenciales de Microsoft 365, ha sido desactivada por la BKA y la ZIT en una operación denominada Olympus Blade». (Inglés)

Vía: @trendaisecurity
Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, With an Assist From TrendAI™
Kratos, the phishing-as-a-Service (PhaaS) platform behind a large share of recent Microsoft 365 credential theft, has been taken offline by the BKA and ZIT in an operation dubbed Olympus Blade.
www.trendmicro.com
August 11, 2026 at 6:29 PM
Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users
Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users
Kratos is a phishing service built to steal Microsoft 365 credentials at scale. It evolved from the Sneaky2FA kit and gave affiliates ready-made login pages, hosting options, and evasion features that made fraudulent sign-ins harder to detect. The operation relied on phishing emails that led targets through trusted-looking services before showing a fake login page. By placing itself between the victim and Microsoft’s real authentication system, Kratos could capture passwords and active session tokens, a technique also seen in  AiTM phishing attack methods  that can weaken the protection offered by multi-factor authentication. Analysts at ANY.RUN identified Kratos as a mature Phishing-as-a-Service platform with a dashboard, anti-bot checks, and automated delivery of stolen information to attackers. ANY.RUN said in a report shared with Cyber Security News (CSN) that the service lowered the skills needed to run convincing Microsoft 365 credential theft campaigns. The reported disruption of Kratos during Operation Olympus Blade in July 2026 did not remove the wider risk. Evolution of Kratos phishing (Source – Any.Run) The service had reportedly supported more than 1,800 subscribers and about 15,000 phishing campaigns each month, while other kits can quickly reuse the same methods to target organizations that depend on Microsoft 365 for daily work. Dismantled Kratos Phishing Kits Acting as Blueprint Kratos was designed as a reusable criminal toolkit rather than a one-off campaign. Its affiliates could imitate familiar services such as document-sharing and creative-software platforms, then send emails that routed victims through SharePoint, OneDrive, Microsoft Forms, Canva, or other legitimate web services before reaching the final trap. That layered delivery model helps criminals evade email filters because the initial link does not always appear to point to a phishing site. Similar social-engineering tactics have recently appeared in  fake Teams update campaigns , where a routine business message is used to make a malicious action seem normal. Kratos phishing email (Source – Any.Run) Before loading a fake Microsoft sign-in form, Kratos could present a CAPTCHA or browser check to screen out automated scanners. Victims then saw a blurred document or invoice with a loading animation, followed by a convincing authentication request intended to create urgency and trust. When a user entered credentials and completed multi-factor authentication, the kit relayed the live session and collected the authentication token. This allowed operators to access the account as an already verified user, meaning a password reset alone might not end the intrusion if active sessions and refresh tokens remain valid. The impact can extend well beyond one mailbox. Attackers with Microsoft 365 access may read business conversations, change payment instructions, steal files from SharePoint, Teams, and OneDrive, or use a trusted account to send new phishing messages to colleagues, customers, and suppliers. Defending Microsoft 365 Accounts Organizations should treat unexpected document-share notices and login prompts as high-risk, especially when they arrive through email, chat, or a link from an unfamiliar website. Users should open Microsoft 365 directly instead of signing in through unsolicited links, while security teams should verify suspicious messages before employees interact with them. Loading page used in Kratos attacks (Source – Any.Run) Defenders should monitor sign-in records for unusual locations, rapid logins from distant places, unfamiliar devices, and signs of token replay. Monitoring mailbox rules is also important because compromised accounts can be used to quietly redirect financial messages or hide security alerts, as covered in  hidden Microsoft 365 mailbox rules . Password resets should be paired with revocation of active sessions and refresh tokens after a suspected account takeover. Security teams should also apply conditional-access controls, use phishing-resistant authentication where possible, and review web logs for unusual redirects or authentication activity. Threat hunting should focus on the reusable pieces left behind by phishing infrastructure, not only on one domain that may disappear quickly. This approach is increasingly important as  phishing kit service operations  make advanced account theft available to more criminals. Indicators of Compromise (IoCs):- Type Indicator Description Domain eimex.com.mx Observed malicious activity associated with Kratos Domain ttressoluciones-my.sharepoint.com Observed malicious activity associated with Kratos Domain grupohuertassa-my.sharepoint.com Observed malicious activity associated with Kratos Domain generlabeton.info Observed malicious activity associated with Kratos Domain feunizar-my.sharepoint.com Observed malicious activity associated with Kratos Domain geoplugin.net Service cited for victim geolocation and filtering File name barr.svg Kratos family-identification asset File name lg.svg Kratos V1 family-identification asset File name dsa.svg Kratos V2 family-identification asset File name sid.gif Kratos V2 family-identification asset File name styles.css Static asset used for campaign linking File name next.php Kratos V1 data-submission endpoint File name save.php Kratos V2 data-submission endpoint File name mini.php Kratos V0 data-submission endpoint SHA-256 c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb lg.svg  hash SHA-256 cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea styles.css  hash Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure. The post Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users appeared first on Cyber Security News .
cybersecuritynews.com
July 28, 2026 at 1:28 PM
Kratos (rebranded Sneaky2FA) is down. BKA/ZIT + US authorities took out 200+ servers, Indonesia arrested the developer. AiTM kit rented to 1,800+ subscribers running ~15K phishing campaigns/month against MS365 accounts. We fed intel since 2025.

www.trendmicro.com/en_us/resear...
Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, With an Assist From TrendAI™
Kratos, the phishing-as-a-Service (PhaaS) platform behind a large share of recent Microsoft 365 credential theft, has been taken offline by the BKA and ZIT in an operation dubbed Olympus Blade.
www.trendmicro.com
July 23, 2026 at 4:01 PM
Kratos phishing-as-a-service is seized - its AiTM proxy stole live M365 session cookies to walk past MFA. https://intel.threadlinqs.com/threat/TL-2026-1613 #ThreatIntel #Kratos #Operation #Sneaky2FA
July 22, 2026 at 8:23 AM
Forg365 phishes M365 with no fake login page - it abuses device-code flow and steals your live session. https://intel.threadlinqs.com/threat/TL-2026-1280 #ThreatIntel #Kali365 #Sneaky2FA #Forg365
July 14, 2026 at 1:09 AM
NovaCookies、Sneaky2FAの後継として台頭するフィッシングサービス

フィッシングサービスは急速に進化し、大規模な悪用を狙った洗練された「ターンキー型」プラットフォームへと変貌を遂げています。最近では、新種のツールキット「NovaCookies」を使った攻撃者が、100件を超えるクラウドアカウントを侵害する事態が発生しました。この深刻な侵害は、単一の医療機関において
NovaCookies、Sneaky2FAの後継として台頭するフィッシングサービス
フィッシングサービスは急速に進化し、大規模な悪用を狙った洗練された「ターンキー型」プラットフォームへと変貌を遂げています。最近では、新種のツールキット「NovaCookies」を使った攻撃者が、100件を超えるクラウドアカウントを侵害する事態が発生しました。この深刻な侵害は、単一の医療機関において
blackhatnews.tokyo
July 8, 2026 at 11:15 AM
Notícia da BleepingComputer

"Sneaky2FA PhaaS kit now uses redteamers' Browser-in-the-Browser attack" #bolhasec
Sneaky2FA PhaaS kit now uses redteamers' Browser-in-the-Browser attack
Sneaky2FA, a popular among cybercriminals phishing-as-a-service (PhaaS) kit, has added Browser-in-the-Browser (BitB) capabilities, giving "customers" the option to launch highly deceptive attacks.
www.bleepingcomputer.com
December 12, 2025 at 4:30 PM
“Sneaky2FA: The phishing scam that steals credentials with browser-in-the-browser attacks” — Red Hot Cyber

#PhishingNews #Scam #Phishing
November 22, 2025 at 8:50 AM