logo

Sneaky2FA PhaaS kit now uses redteamers' Browser-in-the-Browser attack

ID: 4f17d9f5-1168-5d63-85a2-ba24e13a9001

STIX ID: report--4f17d9f5-1168-5d63-85a2-ba24e13a9001

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-11-19

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Sneaky2FA, a widely used phishing-as-a-service targeting Microsoft 365, has added Browser-in-the-Browser (BitB) pop-up capability that mimics legitimate Microsoft login windows to steal both credentials and active session tokens via an AitM reverse-proxy; the kit adapts the fake pop-up to the victim's OS/browser and uses heavy obfuscation and conditional loading to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.