logo

Stealing 2FA Tokens on Red Teams with CredSniper

ID: d08d8bfa-e01f-57a1-a45c-cc84d47e4376

STIX ID: report--d08d8bfa-e01f-57a1-a45c-cc84d47e4376

Feed Name: Black Hills Infosec Blog

Date Published: 2018-08-20

Date Updated: 2026-04-27

Author: BHIS

...
...

CredSniper is an open-source phishing toolkit that clones authentication portals (for example, GSuite) to capture usernames, passwords, and 2FA tokens by proxying or mimicking the genuine authentication flow. The write-up details mandatory HTTPS via automated Let’s Encrypt certificates, a modular Jinja2 template system for creating portal pages, an API and local flat-file formats for retrieving harvested credentials, installation and usage instructions (Ubuntu 16.04 recommended), and operational options for enabling two-factor phishing—making it a practical TTP that can be used by red teams or abused for credential theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.