Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
ID: 297735c1-82b5-52f4-851a-23e1af95bac0
STIX ID: report--297735c1-82b5-52f4-851a-23e1af95bac0
Feed Name: Sekoia.com
Sekoia researchers discovered and analyzed Sneaky 2FA, an Adversary-in-the-Middle phishing kit active since at least October 2024 and sold via a Telegram-based Phishing-as-a-Service called Sneaky Log. The report documents how the kit harvests Microsoft 365 credentials and session cookies (bypassing MFA), its URL patterns and anti-analysis measures (Cloudflare Turnstile, obfuscation, traffic filtering), links to W3LL OV6 code reuse, operator infrastructure and payment workflows, around 100 related domains and IoCs, and provides detection opportunities including an "impossible device shift" correlation rule.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
