Sneaky2FA is a phishing kit associated with adversary-in-the-middle credential theft campaigns targeting Microsoft 365 users, particularly enterprise accounts. It is commonly discussed alongside other phishing-as-a-service ecosystems such as Tycoon2FA and EvilProxy and has been observed using fake Microsoft 365 authentication pages to harvest corporate credentials. The kit has also added Browser-in-the-Browser functionality, displaying a counterfeit browser window and address bar inside the victim’s browser to increase the credibility of phishing prompts and improve social engineering effectiveness.
Operationally, Sneaky2FA has been observed hosted on trusted cloud and content-delivery infrastructure, including major cloud storage and CDN platforms. This hosting model helps operators evade reputation-based filtering because the underlying provider domains are legitimate and widely trusted, while the malicious behavior resides in the served content and user interaction flow. Campaigns associated with this kit are described as enterprise-focused and may filter out free email accounts to prioritize business victims.
Sneaky2FA is best characterized as a credential-harvesting phishing kit rather than a conventional malware payload family. Available reporting links it to phishing activity aimed at account compromise and follow-on abuse of stolen Microsoft 365 access, but does not establish a direct code-level relationship with other kits that share infrastructure or overlapping features.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
It is the direct evolution of Sneaky2FA, an adversary-in-the-middle (AiTM) phishing kit that has targeted Microsoft 365 accounts since October 2024. Sneaky2FA relayed live authentication sessions between a victim and Microsoft's real login servers, letting the operator capture both credentials and session tokens as they passed through.
Sneaky2FA relayed live authentication sessions between a victim and Microsoft's real login servers, letting the operator capture both credentials and session tokens as they passed through, which is what let the kit defeat MFA rather than just harvest a password.
It is the direct evolution of Sneaky2FA, an adversary-in-the-middle (AiTM) phishing kit that has targeted Microsoft 365 accounts since October 2024. Sneaky2FA relayed live authentication sessions between a victim and Microsoft's real login servers, letting the operator capture both credentials and session tokens as they passed through.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another AiTM phishing kit sharing hosting infrastructure with Kratos.
Referenced as another phishing-as-a-service platform with similar features to Forg365.
An AiTM phishing kit offered as a Phishing-as-a-Service toolset, used to capture enterprise credentials and session tokens (including in MFA-protected flows) by acting as a proxy between the victim and legitimate login services.
An AiTM phishing kit offered as a Phishing-as-a-Service platform, used to steal enterprise credentials and session tokens by acting as a proxy between victims and legitimate login services, allowing MFA bypass.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.