Sneaky2FA is an adversary-in-the-middle phishing kit used to steal Microsoft 365 credentials and hijack authenticated sessions in real time, enabling attackers to bypass multi-factor authentication by capturing session tokens after successful login. It is associated with enterprise-focused phishing activity and has been identified as one of the more prevalent AiTM kits used against corporate users. The kit commonly presents fake Microsoft 365 sign-in pages and has also incorporated Browser-in-the-Browser deception to make phishing pages appear more legitimate.
Sneaky2FA is used within broader phishing ecosystems and has appeared as a downstream platform behind redirector infrastructure designed to conceal the final phishing destination from email security controls and automated scanners. It has also been hosted on trusted cloud and CDN services to evade reputation-based detection and increase user trust. Reported activity indicates use against corporate accounts, particularly Microsoft 365 users, with the objective of credential theft and session theft leading to account takeover and follow-on business email compromise or data access.
Sneaky2FA has also been referenced as a precursor or related lineage for later phishing-as-a-service operations such as Kratos, and it shares functional overlap with other AiTM platforms including Tycoon 2FA and EvilProxy. High-confidence reporting supports its role as a phishing kit rather than a standalone malware implant, with core behavior centered on credential harvesting, session interception, and evasion of defensive scanning and filtering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The victim completes their own MFA challenge on the attacker's page, and the resulting authenticated session token is intercepted before it reaches the victim.
Confirmed downstream platforms include Sneaky2FA and Tycoon 2FA, adversary-in-the-middle kits that bypass MFA by intercepting the authenticated session in real time.
Sneaky2FA relayed live authentication sessions between a victim and Microsoft's real login servers, letting the operator capture both credentials and session tokens as they passed through, which is what let the kit defeat MFA rather than just harvest a password.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Adversary-in-the-middle phishing kit used downstream of the Bulletproof blind redirector to harvest Microsoft credentials and intercept authenticated sessions in real time, enabling MFA bypass via session theft.
A precursor phishing kit from which Kratos evolved, associated with credential theft and adversary-in-the-middle phishing workflows.
Mentioned only as another AiTM phishing kit sharing hosting infrastructure with Kratos.
Referenced as another phishing-as-a-service platform with similar features to Forg365.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.