Sneaky 2FA
Sneaky 2FA is a phishing-as-a-service (PhaaS) kit identified as an aggressive newer entrant in the MFA-bypass phishing ecosystem. Reporting cited it as one of the groups that benefited from the disruption of Tycoon 2FA, with monthly attack volume reportedly rising from under 700,000 to nearly 2 million around that period. Barracuda described it as one of the phishing kits that moved quickly to fill the gap left by Tycoon 2FA. Sneaky 2FA uses adversary-in-the-middle (AitM) techniques to bypass multi-factor authentication. Reported capabilities include validating stolen credentials through legitimate Microsoft APIs, evading bots and sandboxes, using browser-in-the-browser fake login windows, and redirecting victims to Microsoft-related pages to reduce suspicion. The provided content does not attribute Sneaky 2FA to a specific nation state or identify additional aliases or sub-groups beyond the name Sneaky 2FA.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newer phishing platform described as an aggressive newcomer benefiting from the ecosystem shift after Tycoon 2FA's takedown.
A phishing-as-a-service group that increased activity following Tycoon 2FA's takedown.
Sneaky 2FA is a phishing kit specializing in bypassing multi-factor authentication using adversary-in-the-middle techniques and advanced evasion methods.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.