Sneaky2FA Phishing Kit Enhances Tactics with Browser-in-the-Browser Functionality
First seen 2 Dec 2025, 18:33 UTC
•


•85% similarity
•30.2
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Sneaky2FA phishing-as-a-service kit has been upgraded to include Browser-in-the-Browser (BITB) techniques, allowing attackers to create deceptive phishing pages that mimic legitimate login interfaces. This evolution targets Microsoft 365 accounts by embedding fake login forms within a browser window on the victim's desktop, effectively stealing credentials and session cookies. The kit's recent capabilities indicate a significant advancement in phishing tactics.
ThreatCluster AI