Sneaky 2FA is a phishing-as-a-service platform focused on compromising Microsoft 365 accounts by bypassing multi-factor authentication through adversary-in-the-middle techniques. Active since at least October 2024 and publicly identified in December 2024, it operates as a commercial cybercrime service and has been associated with the Sneaky Log branding. Known aliases include Sneaky2FA and sneaky_2fa. The platform relays victim authentication traffic to legitimate Microsoft services, captures authenticated session artifacts, and validates stolen credentials through Microsoft APIs. Its operators and customers use the kit to obtain account access without defeating MFA cryptographically, instead abusing legitimate authentication flows and stealing the resulting session state. Reported lure formats include document-themed phishing and QR-code-based delivery. Sneaky 2FA is notable for strong anti-analysis and evasion features. Reported capabilities include CAPTCHA gating, IP-based filtering, redirection of suspected researchers or automated scanners to benign Microsoft-related content, heavily obfuscated HTML and JavaScript, anti-debugging measures, and browser-in-the-browser functionality that imitates legitimate login pop-ups with convincing browser chrome. It also uses randomized and rapidly replaced phishing URLs to reduce the effectiveness of reputation-based blocking. The kit is distributed through Telegram and has been described as providing customers with licensed, obfuscated code for independent deployment. Reporting has also indicated code reuse or overlap with other phishing kits in the Microsoft 365-focused PhaaS ecosystem, including similarities to W3LL OV6 and feature overlap with platforms such as Kali365 and Forg365, although not all claimed relationships are established at the same confidence level. Sneaky 2FA emerged as a prominent successor in the market shift that followed disruption of Tycoon 2FA infrastructure, alongside services such as EvilProxy, Mamba 2FA, and Whisper 2FA. Its role in that ecosystem reflects the broader evolution of identity-centric phishing operations toward session hijacking, MFA bypass, and increasingly polished social-engineering tradecraft aimed at enterprise cloud accounts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-as-a-Service platform conducting AiTM phishing against Microsoft 365 to relay credentials to Microsoft and steal authenticated session cookies after victims complete real MFA.
Mentioned only as another PhaaS platform with similar features to Forg365; no direct connection established in the article.
A newer phishing platform described as an aggressive newcomer benefiting from the ecosystem shift after Tycoon 2FA's takedown.
A phishing-as-a-service group that increased activity following Tycoon 2FA's takedown.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.