Sneaky 2FA is a phishing-as-a-service adversary-in-the-middle kit used to target Microsoft 365 accounts and bypass multi-factor authentication by proxying the legitimate Microsoft sign-in flow in real time. It is associated with credential theft and session theft against enterprise users, including campaigns aimed at organizations in healthcare, education, manufacturing, government, professional services, and enterprise IT functions.
The kit is designed to intercept Microsoft authentication workflows rather than rely on static credential-harvesting pages. Reported capabilities include capture and validation of usernames and passwords, interception of one-time passcodes and other MFA challenges, and theft of authenticated session material that can be reused after login. Observed tradecraft also includes credential validation through legitimate Microsoft APIs, browser-in-the-browser style fake login windows, and redirection to legitimate Microsoft-related pages after capture to reduce victim suspicion.
Sneaky 2FA has been observed in phishing campaigns using trusted redirectors and layered URL wrapping to evade static analysis, as well as anti-bot and anti-analysis controls such as browser fingerprinting, geolocation checks, honeypots, timing checks, mouse-interaction checks, WebGL and canvas inspection, and headless-browser or debugger detection. Researchers have also described mutable loader and routing components wrapped around more stable core phishing modules, indicating ongoing efforts to hinder detection and signature-based tracking.
Campaigns linked to Sneaky 2FA have used Microsoft-themed security alerts and voicemail-style lures delivered through email, including messages sent from compromised third-party SaaS accounts to improve trust and deliverability. The kit has also been discussed as part of a broader ecosystem of Microsoft-focused AiTM and PhaaS platforms alongside EvilProxy, Mamba 2FA, Whisper 2FA, Kali365, EvilTokens, FlowerStorm, and Tycoon 2FA-derived activity. Some reporting refers to the kit as WikiKit.
Sneaky 2FA is best characterized as a phishing kit and service platform for credential and session theft against cloud identity workflows, especially Microsoft 365, with strong emphasis on MFA bypass, anti-analysis, and operational flexibility for affiliates.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts. The BKA said compromised accounts were often used to carry out further crimes.
MITRE ATT&CK Mapping Technique ID Technique Applies To T1078.004 Valid Accounts: Cloud Accounts All three (post-compromise)
Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts. The BKA said compromised accounts were often used to carry out further crimes.
Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts. The BKA said compromised accounts were often used to carry out further crimes.
TTP # T1027 — Obfuscated Files or Information (Defense Evasion)
This technique presents a simulated browser window and address bar inside the phishing page, making the authentication prompt appear to originate from a legitimate Microsoft domain.
Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts. The BKA said compromised accounts were often used to carry out further crimes.
The platform relayed victims’ credentials and MFA responses to legitimate login services before capturing authenticated session cookies.
TTP # T1556.006 — Modify Authentication Process: Multi-Factor Authentication (Credential Access)
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adversary-in-the-middle phishing kit referenced as another toolkit delivered through similar redirect infrastructure.
A phishing kit/ecosystem referenced as comparable to Forg365 and used in credential theft campaigns involving Microsoft-themed phishing flows and redirection chains.
Kit de phishing AiTM ciblant les comptes Microsoft. Il implémente un workflow complet de connexion Microsoft pour collecter mot de passe, OTP, code SMS, approbation Authenticator/push MFA, number matching et potentiellement les cookies de session, avec replay quasi temps réel des identifiants vers Microsoft Entra ID. Il inclut aussi des fonctions anti-analyse et de browser-gating.
A newer phishing kit/platform identified as an aggressive newcomer filling the gap left by Tycoon 2FA.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.