Last seven days
- First activity
- Jul 24, 2026
- Last activity
- Jul 28, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 56 hostnames
Sneaky2FA is a phishing kit associated with adversary-in-the-middle credential theft campaigns targeting Microsoft 365 users, particularly enterprise accounts.
Profile source: Mallory opens in a new tabSneaky2FA
Sneaky2FA is a phishing kit associated with adversary-in-the-middle credential theft campaigns targeting Microsoft 365 users, particularly enterprise accounts. It is commonly discussed alongside other phishing-as-a-service ecosystems such as Tycoon2FA and EvilProxy and has been observed using fake Microsoft 365 authentication pages to harvest corporate credentials. The kit has also added Browser-in-the-Browser functionality, displaying a counterfeit browser window and address bar inside the victim’s browser to increase the credibility of phishing prompts and improve social engineering effectiveness.
Operationally, Sneaky2FA has been observed hosted on trusted cloud and content-delivery infrastructure, including major cloud storage and CDN platforms. This hosting model helps operators evade reputation-based filtering because the underlying provider domains are legitimate and widely trusted, while the malicious behavior resides in the served content and user interaction flow. Campaigns associated with this kit are described as enterprise-focused and may filter out free email accounts to prioritize business victims.
Sneaky2FA is best characterized as a credential-harvesting phishing kit rather than a conventional malware payload family. Available reporting links it to phishing activity aimed at account compromise and follow-on abuse of stolen Microsoft 365 access, but does not establish a direct code-level relationship with other kits that share infrastructure or overlapping features.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.