Last seven days
- First activity
- Sep 5, 2026
- Last activity
- Sep 5, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
Sneaky2FA is an adversary-in-the-middle phishing kit used to steal Microsoft 365 credentials and hijack authenticated sessions in real time, enabling attackers to bypass multi-factor authentication by capturing session tokens after successful login.
Profile source: Mallory opens in a new tabSneaky2FA
Sneaky2FA is an adversary-in-the-middle phishing kit used to steal Microsoft 365 credentials and hijack authenticated sessions in real time, enabling attackers to bypass multi-factor authentication by capturing session tokens after successful login. It is associated with enterprise-focused phishing activity and has been identified as one of the more prevalent AiTM kits used against corporate users. The kit commonly presents fake Microsoft 365 sign-in pages and has also incorporated Browser-in-the-Browser deception to make phishing pages appear more legitimate.
Sneaky2FA is used within broader phishing ecosystems and has appeared as a downstream platform behind redirector infrastructure designed to conceal the final phishing destination from email security controls and automated scanners. It has also been hosted on trusted cloud and CDN services to evade reputation-based detection and increase user trust. Reported activity indicates use against corporate accounts, particularly Microsoft 365 users, with the objective of credential theft and session theft leading to account takeover and follow-on business email compromise or data access.
Sneaky2FA has also been referenced as a precursor or related lineage for later phishing-as-a-service operations such as Kratos, and it shares functional overlap with other AiTM platforms including Tycoon 2FA and EvilProxy. High-confidence reporting supports its role as a phishing kit rather than a standalone malware implant, with core behavior centered on credential harvesting, session interception, and evasion of defensive scanning and filtering.
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.