Skip to content

Sneaky2FA

Sneaky2FA is a phishing kit used in enterprise-focused credential theft campaigns, particularly against Microsoft 365 users.

Profile source: Mallory opens in a new tab

Sneaky2FA

Family profile

Sneaky2FA is a phishing kit used in enterprise-focused credential theft campaigns, particularly against Microsoft 365 users. It is associated with adversary-in-the-middle phishing operations designed to capture account credentials and, in related ecosystem reporting, session material that can undermine the practical protection provided by multi-factor authentication. The kit has been observed presenting fake Microsoft 365 login pages and later adding Browser-in-the-Browser functionality to make fraudulent authentication prompts appear more convincing.

Sneaky2FA has been discussed alongside other prominent phishing-as-a-service and AiTM kits such as Tycoon2FA and EvilProxy, and it is part of a broader ecosystem of reusable criminal tooling aimed at lowering the barrier to large-scale account compromise. Reporting also notes that the Kratos platform evolved from the Sneaky2FA kit, indicating that Sneaky2FA contributed to the lineage of more mature affiliate-oriented phishing services.

Operationally, Sneaky2FA has been hosted on trusted cloud and CDN infrastructure, including major storage and content-delivery platforms, to evade reputation-based filtering and increase victim trust in the delivery chain. Its campaigns have used fake Microsoft 365 authentication pages to harvest corporate credentials, and the addition of Browser-in-the-Browser techniques reflects an emphasis on deception and defense evasion rather than malware execution on the endpoint.

Sneaky2FA targets enterprise identities rather than local systems, with the primary impact being account takeover risk, follow-on business email compromise, and unauthorized access to cloud-hosted business data and communications. It is best characterized as phishing infrastructure and credential-harvesting tooling rather than conventional host-resident malware.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Spoofing

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 4, 2026
Feed role
Distribution
Host form
0 IP / 17 hostnames

Leading locations

  • US17

Leading providers

  • Cloudflare, Inc.16
  • Oracle Corporation1

Infrastructure traits

  • Hosting 17
  • Anycast 16
  • Proxy 1

MITRE ATT&CK

Sneaky2FA in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.