Stealing 2FA Tokens on Red Teams with CredSniper
ID: d08d8bfa-e01f-57a1-a45c-cc84d47e4376
STIX ID: report--d08d8bfa-e01f-57a1-a45c-cc84d47e4376
Feed Name: Black Hills Infosec Blog
CredSniper is an open-source phishing toolkit that clones authentication portals (for example, GSuite) to capture usernames, passwords, and 2FA tokens by proxying or mimicking the genuine authentication flow. The write-up details mandatory HTTPS via automated Let’s Encrypt certificates, a modular Jinja2 template system for creating portal pages, an API and local flat-file formats for retrieving harvested credentials, installation and usage instructions (Ubuntu 16.04 recommended), and operational options for enabling two-factor phishing—making it a practical TTP that can be used by red teams or abused for credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
