Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New 'Sneaky 2FA' Phishing Kit Targets Microsoft 365 Accounts with 2FA Code Bypass
thehackernews.com ^ | 01/17/2025 | Ravie Lakshmanan

Posted on 01/21/2025 8:22:25 AM PST by BenLurkin

Nearly 100 domains hosting Sneaky 2FA phishing pages have been identified as of this month, suggesting moderate adoption by threat actors.

"This kit is being sold as phishing-as-a-service (PhaaS) by the cybercrime service 'Sneaky Log,' which operates through a fully-featured bot on Telegram," the company said in an analysis. "Customers reportedly receive access to a licensed obfuscated version of the source code and deploy it independently."

Phishing campaigns have been observed sending payment receipt-related emails to entice recipients into opening bogus PDF documents containing QR code that, upon scanning, redirects them to Sneaky 2FA page

Sekoia said the phishing pages are hosted on compromised infrastructure, mostly involving WordPress websites and other domains controlled by the attacker. The fake authentication pages are designed to automatically populate the victim's email address to elevate their legitimacy.

The kit also boasts of several anti-bot and anti-analysis measures, employing techniques like traffic filtering and Cloudflare Turnstile challenges to ensure that only victims who meet certain criteria are directed to the credential harvesting pages. It further runs a series of checks to detect and resist analysis attempts using web browser developer tools.

A notable aspect of the PhaaS is that site visitors whose IP address originates from a data center, cloud provider, bot, proxy, or VPN are directed to a Microsoft-related Wikipedia page using the href[.]li redirection service. This behavior has led TRAC Labs to give it the name WikiKit.

"The Sneaky 2FA phishing kit employs several blurred images as the background for its fake Microsoft authentication pages," Sekoia explained. "By using screenshots of legitimate Microsoft interfaces, this tactic is intended to deceive users into authenticating themselves to gain access to the blurred content."

(Excerpt) Read more at thehackernews.com ...


TOPICS: Computers/Internet
KEYWORDS: cybersecurity; hacking; phishing; sneaky2fa; telegram; telegraph

1 posted on 01/21/2025 8:22:25 AM PST by BenLurkin
[ Post Reply | Private Reply | View Replies]

To: BenLurkin; rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; ...

2 posted on 01/21/2025 8:23:19 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

PM


3 posted on 01/21/2025 8:30:37 AM PST by Ken Regis (I concur )
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

4 posted on 01/21/2025 8:32:42 AM PST by Frank Drebin (And don't ever let me catch you guys in America!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce

5 posted on 01/21/2025 10:03:20 AM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 2 | View Replies]

To: BenLurkin

I am so close to getting rid of microsoft products. The engineering software I use if getting very close to being completely cloud based running on any browser. it’s not quite ready yet but after, easily, $100,000 in software subscriptions and more for hardware, being self employed is enough for me. I am perfectly happy with my old machines running windows 7 or even my old XP boxes running my CMM and CNC machines. Soon....


6 posted on 01/21/2025 10:33:23 AM PST by Organic Panic (Democrats. Memories as short as Joe Biden's eyes)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

You can buy Office 2021 or 2019 for under $35
One time payment. Not much changes in Office. Why rent?


7 posted on 01/21/2025 11:39:16 PM PST by minnesota_bound (Need more money to buy everything now)
[ Post Reply | Private Reply | To 1 | View Replies]

To: minnesota_bound

+1

With the 365 version, I think there are enticements in the corporate setting around “collaboration”, Microsoft Teams (chat/video conferencing), OneDrive (file sharing), and Copilot (ChatGPT AI).

See also “Microsoft Delve”, etc...


8 posted on 01/24/2025 8:26:38 AM PST by mbj
[ Post Reply | Private Reply | To 7 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson