Sneaky2FA Phishing Kit Enhances Techniques with Browser-in-the-Browser Functionality
First seen 23 Nov 2025, 12:26 UTC
•


•85% similarity
•35.7
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Sneaky2FA phishing-as-a-service kit has integrated Browser-in-the-Browser (BITB) techniques to enhance its ability to steal Microsoft 365 credentials. This updated functionality allows attackers to create deceptive phishing pages that mimic legitimate login interfaces, effectively bypassing multi-factor authentication (MFA) measures. Victims are directed to fraudulent sites where their credentials and session cookies can be compromised.
ThreatCluster AI