Sneaky2FA Phishing Kit Enhances Techniques with Browser-in-the-Browser Functionality

Sneaky2FA Phishing Kit Enhances Techniques with Browser-in-the-Browser Functionality

First seen 23 Nov 2025, 12:26 UTC ScworldTechnaduBleepingcomputerCsoonline 85% similarity 35.7

Article Content

Browse articles
ThreatCluster

The Sneaky2FA phishing-as-a-service kit has integrated Browser-in-the-Browser (BITB) techniques to enhance its ability to steal Microsoft 365 credentials. This updated functionality allows attackers to create deceptive phishing pages that mimic legitimate login interfaces, effectively bypassing multi-factor authentication (MFA) measures. Victims are directed to fraudulent sites where their credentials and session cookies can be compromised.

ThreatCluster AI

Community

Browse all →