Threat intelligence reporting describes mobile phishing kits evolving to coordinate web-based credential harvesting with live voice social engineering (vishing). The kits reportedly let operators update phishing pages in real time during a phone call—prompting victims to enter credentials and MFA/2FA codes on mobile browsers in sync with the caller’s instructions—raising the likelihood of successful account takeover, particularly where organizations rely on non-phishing-resistant MFA methods.
Separate mobile-security coverage highlights risks to 2FA code confidentiality on-device, including a disclosed issue in a mobile authenticator workflow where other apps could potentially access clipboard contents during code generation/entry, undermining 2FA protections if exploited on the same handset. Additional content in the set includes a general mobile app pentest write-up (not clearly tied to 2FA or the vishing-synced phishing kits) and a product showcase for the 2FAS Auth iOS authenticator, which is primarily promotional and not part of the same specific threat reporting.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Threat intelligence reporting described mobile-focused phishing kits that can update phishing pages in real time during a phone call, allowing attackers to align on-screen prompts with live social engineering. The technique increases the likelihood of stealing credentials and one-time MFA codes from victims using mobile browsers.
Following disclosure of the mobile authentication app weakness, guidance emphasized strengthening inter-app boundaries, tightening permission controls, and promptly installing mobile app updates to reduce clipboard leakage risk. The response framed mobile endpoint security as critical because compromised phones can undermine otherwise strong MFA protections.
A vulnerability in a widely used mobile authentication app was disclosed, showing that other apps on the same smartphone could potentially read clipboard contents while 2FA codes were being generated or entered. The issue raised the risk of unauthorized account access by weakening the integrity of the 2FA process on mobile devices.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.