Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sneaky2FA Microsoft 365 BitB phishing campaign

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The Sneaky2FA phishing operation has added browser-in-the-browser (BitB) lures on top of its existing AitM flow, making credential and session theft more convincing against Microsoft 365 accounts. The kit uses fake Microsoft sign-in windows to steal credentials and active session tokens, which can bypass 2FA protections. It also relies on previewdoc[.]com, Cloudflare Turnstile checks, and conditional loading to increase success and reduce detection.

Related Happenings

Jalisco and OmegaLord Microsoft 365 phishing kits

Malware Activity
H score27 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...

ClickFix payload delivery analysis exposes API-driven generation and Downloads-folder AMSI evasion

Technical Analysis
H score74 First: 01.07.2026 08:32 Last: 01.07.2026 08:32 Sources 1

About this happening: Analysis of ClickFix payload delivery shows operators moving to API-driven servers and a Downloads-folder orchestrator, increasing stealth across live campaigns. The b...

TCLBANKER banking trojan activity targeting 59 financial platforms

Malware Activity
H score20 First: 08.05.2026 21:12 Last: 08.05.2026 21:12 Sources 1

About this happening: TCLBANKER is a newly documented Brazilian banking trojan that can hit 59 banking, fintech, and cryptocurrency platforms, increasing the risk of credential theft and re...

Snow malware suite deployment by UNC6692

Malware Activity
H score29 First: 25.04.2026 18:07 Last: 25.04.2026 18:07 Sources 1

About this happening: UNC6692 has deployed the Snow malware suite through social engineering, creating a stealthy path to credential theft and domain compromise. The operation uses em...

OAuth device-code phishing campaign targeting SaaS accounts

Campaign
H score43 First: 04.04.2026 17:17 Last: 04.04.2026 17:17 Sources 1

About this happening: A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...

Timeline

  1. 19.11.2025 23:59 2 articles · 7mo ago

    Sneaky2FA adds BitB Microsoft login lure

    Initial Disclosure

    Sneaky2FA’s phishing-as-a-service kit now uses a browser-in-the-browser pop-up that mimics a legitimate Microsoft login window, adaptively styled for the victim’s OS and browser, to steal Microsoft credentials and active session tokens through its existing attacker-in-the-middle reverse-proxy flow against Microsoft 365 accounts. The phishing chain uses previewdoc[.]com, a Cloudflare Turnstile bot check, conditional loading, and heavily obfuscated HTML and JavaScript to reduce detection.

    Show sources