Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Threats and Vulnerabilities - Sneaky 2FA Kit Exposes Vulnerabilities in 2FA Security
Threats and Vulnerabilities Data Protection Identity & Access Management Latest News News & Analysis

Sneaky 2FA Kit Exposes Vulnerabilities in 2FA Security

Kirsten DoyleBy Kirsten DoyleJanuary 20, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
2FA
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cybersecurity researchers from Sekoia have discovered a new Adversary-in-the-Middle (AiTM) phishing kit named “Sneaky 2FA,” targeting Microsoft 365 accounts.

First discovered in December last year, this phishing kit has been active since at least October 2024 and is distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot called “Sneaky Log.” Subscribers receive an obfuscated version of the source code, allowing them to deploy the phishing kit independently.

Bypassing 2FA

This scourge has several key features:

  • Autograb Functionality: The phishing URLs include the victim’s email address as a parameter, which is then prefilled into the fake Microsoft authentication page to make it seem credible.
  • Anti-Bot and Anti-Analysis Measures: It then uses traffic filtering and Cloudflare Turnstile challenges to make sure that only legitimate users are directed to the credential harvesting pages. Moreover, it carries out checks to detect and resist any analysis attempts using web browser developer tools.
  • Session Hijacking: By wedging itself between the user and the legitimate service, the kit captures session cookies once the user has completed the 2FA process, which enables malefactors to bypass 2FA and get access to user accounts.

Readily Available for Purchase

Elad Luz, Head of Research at Oasis Security, says this threat is particularly deceptive for several reasons. “The links in the phishing emails are crafted to pass the victim’s email address to the login page, enabling it to ‘autofill’ the email field. This mimics the behavior of legitimate websites, where autofill is typically associated with accounts users have previously logged into.”

In addition, he says the attackers obfuscated screenshots of Microsoft webpages to mimic a convincing login background, making it seem as though users will access legitimate content once successfully logged in. “They also implemented common methods on the web page to distinguish between humans and bots. If the visitor is detected as a bot, the page either displays harmless content or redirects to a legitimate website like Wikipedia. This tactic helps evade automated detection by security systems.”

Luz says Sneaky 2FA was developed by one group of malicious actors and sold to others, emphasizing the collaborative nature of many attacks we see today—in fact, these types of tools are often the result of collaborative efforts by different actors working together and trading resources. “The fact that such kits are readily available for purchase is highly concerning.”

Distribution and Operations

The phishing kit costs a measly $200 per month and operates through a fully featured Telegram bot. Customers get access to a licensed, obfuscated version of the source code and can deploy it independently.

The phishing pages are hosted on compromised infrastructure, usually WordPress websites and other domains controlled by the kit’s authors.

The researchers said that analysis of the source code revealed references to a phishing syndicate named W3LL Store, previously exposed for distributing a phishing kit called W3LL Panel. Similarities in the AiTM relay implementation suggest that Sneaky 2FA could be based on the W3LL Panel.

Entities are advised to monitor for any anomalous User-Agent transitions that happen during authentication processes, as Sneaky 2FA uses a range of hardcoded User-Agent strings depending on the authentication step.

Protecting Against Sneaky 2FA

Stephen Kowski, Field CTO at SlashNext, says the kit is a full-featured PhaaS platform with real-time credential and session cookie theft capabilities, and is particularly dangerous for Microsoft 365 environments. “Protection requires phishing-resistant authentication methods like FIDO2/WebAuthn, real-time URL scanning at the time of click that completely bypasses Cloudflare Turnstile protection and proactive detection of newly registered phishing domains before they become active threats.”

Patrick Tiquet, Vice President of Security & Architecture at Keeper Security, says firms can mitigate this risk by implementing Privileged Access Management (PAM) to restrict access and contain potential damage from compromised accounts. Pairing this with robust password management ensures that credentials are strong, unique, and securely stored, reducing exposure to phishing campaigns. “Additionally, a password manager will prevent users from entering credentials into spoofed websites because the tool will only auto-fill credentials on the authentic webpage. Enforcing layered security measures, such as advanced threat detection and employee training, further minimize organizational risk.”

To mitigate the risks associated with sophisticated phishing kits, Luz advises implementing advanced threat detection solutions that monitor sign-in logs and deploy effective tools to fingerprint attackers and detect anomalies. Education is also key, and users are advised to exercise extreme caution with emails and verify the legitimacy of websites before entering their credentials.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

June 2, 20263 Mins Read

How EM is boosting the career trajectory of VM analysts

May 19, 20266 Mins Read

Microsoft patches 138 vulnerabilities as AI-driven discovery accelerates

May 14, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}