Sneaky2FA is a phishing-as-a-service (PhaaS) operation that enables credential theft and session hijacking against cloud identity platforms, including campaigns designed to capture usernames, passwords, and multi-factor authentication codes in real time. It is associated with reverse-proxy phishing workflows and has incorporated browser-in-the-browser (BITB) functionality, allowing operators to present convincing fake browser login windows with spoofed address bars to increase the realism of phishing lures and bypass user suspicion. The service lowers the barrier to entry for financially motivated threat actors by providing customers with a packaged phishing capability delivered through a Telegram-based bot and licensed, obfuscated source code for independent deployment. Its tradecraft emphasizes evasion and operational resilience. Reported defensive bypass features include anti-analysis logic, mechanisms to detect or interfere with browser developer tools, and heavily obfuscated HTML and JavaScript intended to frustrate static inspection and signature-based detection. Observed implementations also use techniques such as fragmenting visible interface text and rendering interface components as encoded images to reduce straightforward content-based detection. Sneaky2FA campaigns have been linked to rapid infrastructure rotation and burn-and-replace URL tactics, helping operators evade reputation-based blocking and shorten defender response windows. The platform’s BITB capability reflects a broader evolution in phishing operations toward more convincing identity attacks that can defeat traditional email and web filtering controls as well as user familiarity with standard login prompts. Compromise through these methods can enable downstream access to enterprise applications via stolen sessions and single sign-on abuse. Sneaky2FA has been discussed alongside other Microsoft 365-focused PhaaS ecosystems such as Kali365 and Forg365 because of overlapping feature sets, although a definitive operational connection is not established. It is best characterized as a mature criminal phishing service focused on scalable identity compromise, MFA interception, and detection evasion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another PhaaS platform with similar features to Forg365; no direct connection established in the article.
Sneaky2FA is a phishing-as-a-service kit that enables threat actors to bypass multi-factor authentication (MFA) by using advanced browser-in-the-browser (BITB) phishing techniques. It provides customizable, obfuscated phishing pages that capture credentials and MFA codes, allowing attackers to hijack live sessions and access enterprise cloud accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.