Skip to content

Sneaky2FA

Sneaky2FA is a phishing kit associated with adversary-in-the-middle credential theft campaigns targeting Microsoft 365 users, particularly enterprise accounts.

Profile source: Mallory opens in a new tab

Sneaky2FA

Family profile

Sneaky2FA is a phishing kit associated with adversary-in-the-middle credential theft campaigns targeting Microsoft 365 users, particularly enterprise accounts. It is commonly discussed alongside other phishing-as-a-service ecosystems such as Tycoon2FA and EvilProxy and has been observed using fake Microsoft 365 authentication pages to harvest corporate credentials. The kit has also added Browser-in-the-Browser functionality, displaying a counterfeit browser window and address bar inside the victim’s browser to increase the credibility of phishing prompts and improve social engineering effectiveness.

Operationally, Sneaky2FA has been observed hosted on trusted cloud and content-delivery infrastructure, including major cloud storage and CDN platforms. This hosting model helps operators evade reputation-based filtering because the underlying provider domains are legitimate and widely trusted, while the malicious behavior resides in the served content and user interaction flow. Campaigns associated with this kit are described as enterprise-focused and may filter out free email accounts to prioritize business victims.

Sneaky2FA is best characterized as a credential-harvesting phishing kit rather than a conventional malware payload family. Available reporting links it to phishing activity aimed at account compromise and follow-on abuse of stolen Microsoft 365 access, but does not establish a direct code-level relationship with other kits that share infrastructure or overlapping features.

Capabilities

  • Credential Theft
  • Spoofing

Observed infrastructure

Last seven days

First activity
Jul 24, 2026
Last activity
Jul 28, 2026
Feed role
Distribution
Host form
0 IP / 56 hostnames

Leading locations

  • US52
  • IE1

Leading providers

  • Cloudflare, Inc.52
  • Microsoft Corporation1

Infrastructure traits

  • Hosting 53
  • Anycast 52
  • Proxy 2

MITRE ATT&CK

Sneaky2FA in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.