logo

Attackers are using “Sneaky 2FA” to create fake sign-in windows that look real

ID: 189ef849-c438-5238-8cbc-1b20a6a1fa35

STIX ID: report--189ef849-c438-5238-8cbc-1b20a6a1fa35

Feed Name: Malwarebytes Blog

Threat Score
50/100

Date Published: 2025-11-19

Date Updated: 2026-04-28

...
...

Researchers observed a phishing campaign leveraging a Phishing-as-a-Service kit dubbed "Sneaky 2FA" that creates highly convincing fake browser pop-up login windows (Browser-in-the-Browser) to capture credentials; attackers tailor the fake window to the visitor's OS/browser, selectively display pages to high-value targets, and use short‑lived domains to evade blocks. Recommended mitigations include consistent use of password managers, multi-factor authentication, cautious link handling, and heuristic browser protections such as Malwarebytes Browser Guard.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.