Skip to content

Sneaky2FA

Sneaky2FA is an adversary-in-the-middle phishing kit used to steal Microsoft 365 credentials and hijack authenticated sessions in real time, enabling attackers to bypass multi-factor authentication by capturing session tokens after successful login.

Profile source: Mallory opens in a new tab

Sneaky2FA

Family profile

Sneaky2FA is an adversary-in-the-middle phishing kit used to steal Microsoft 365 credentials and hijack authenticated sessions in real time, enabling attackers to bypass multi-factor authentication by capturing session tokens after successful login. It is associated with enterprise-focused phishing activity and has been identified as one of the more prevalent AiTM kits used against corporate users. The kit commonly presents fake Microsoft 365 sign-in pages and has also incorporated Browser-in-the-Browser deception to make phishing pages appear more legitimate.

Sneaky2FA is used within broader phishing ecosystems and has appeared as a downstream platform behind redirector infrastructure designed to conceal the final phishing destination from email security controls and automated scanners. It has also been hosted on trusted cloud and CDN services to evade reputation-based detection and increase user trust. Reported activity indicates use against corporate accounts, particularly Microsoft 365 users, with the objective of credential theft and session theft leading to account takeover and follow-on business email compromise or data access.

Sneaky2FA has also been referenced as a precursor or related lineage for later phishing-as-a-service operations such as Kratos, and it shares functional overlap with other AiTM platforms including Tycoon 2FA and EvilProxy. High-confidence reporting supports its role as a phishing kit rather than a standalone malware implant, with core behavior centered on credential harvesting, session interception, and evasion of defensive scanning and filtering.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Session Hijacking

Observed infrastructure

Last seven days

First activity
Sep 5, 2026
Last activity
Sep 5, 2026
Feed role
Distribution
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

Sneaky2FA in ATT&CK

5 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.