Sneaky2FA Microsoft 365 BitB phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The Sneaky2FA phishing operation has added browser-in-the-browser (BitB) lures on top of its existing AitM flow, making credential and session theft more convincing against Microsoft 365 accounts. The kit uses fake Microsoft sign-in windows to steal credentials and active session tokens, which can bypass 2FA protections. It also relies on previewdoc[.]com, Cloudflare Turnstile checks, and conditional loading to increase success and reduce detection.
Related Happenings
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
ClickFix payload delivery analysis exposes API-driven generation and Downloads-folder AMSI evasion
Technical Analysis
H score74
First: 01.07.2026 08:32
Last: 01.07.2026 08:32
Sources 1
About this happening:
Analysis of ClickFix payload delivery shows operators moving to API-driven servers and a Downloads-folder orchestrator, increasing stealth across live campaigns. The b...
ClickFix payload delivery analysis exposes API-driven generation and Downloads-folder AMSI evasion
Technical AnalysisAbout this happening: Analysis of ClickFix payload delivery shows operators moving to API-driven servers and a Downloads-folder orchestrator, increasing stealth across live campaigns. The b...
TCLBANKER banking trojan activity targeting 59 financial platforms
Malware Activity
H score20
First: 08.05.2026 21:12
Last: 08.05.2026 21:12
Sources 1
About this happening:
TCLBANKER is a newly documented Brazilian banking trojan that can hit 59 banking, fintech, and cryptocurrency platforms, increasing the risk of credential theft and re...
TCLBANKER banking trojan activity targeting 59 financial platforms
Malware ActivityAbout this happening: TCLBANKER is a newly documented Brazilian banking trojan that can hit 59 banking, fintech, and cryptocurrency platforms, increasing the risk of credential theft and re...
Snow malware suite deployment by UNC6692
Malware Activity
H score29
First: 25.04.2026 18:07
Last: 25.04.2026 18:07
Sources 1
About this happening:
UNC6692 has deployed the Snow malware suite through social engineering, creating a stealthy path to credential theft and domain compromise. The operation uses em...
Snow malware suite deployment by UNC6692
Malware ActivityAbout this happening: UNC6692 has deployed the Snow malware suite through social engineering, creating a stealthy path to credential theft and domain compromise. The operation uses em...
OAuth device-code phishing campaign targeting SaaS accounts
Campaign
H score43
First: 04.04.2026 17:17
Last: 04.04.2026 17:17
Sources 1
About this happening:
A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...
OAuth device-code phishing campaign targeting SaaS accounts
CampaignAbout this happening: A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...
Timeline
-
19.11.2025 23:59 2 articles · 7mo ago
Sneaky2FA adds BitB Microsoft login lure
Initial DisclosureSneaky2FA’s phishing-as-a-service kit now uses a browser-in-the-browser pop-up that mimics a legitimate Microsoft login window, adaptively styled for the victim’s OS and browser, to steal Microsoft credentials and active session tokens through its existing attacker-in-the-middle reverse-proxy flow against Microsoft 365 accounts. The phishing chain uses previewdoc[.]com, a Cloudflare Turnstile bot check, conditional loading, and heavily obfuscated HTML and JavaScript to reduce detection.
Show sources
- Sneaky2FA PhaaS kit now uses redteamers' Browser-in-the-Browser attack — www.bleepingcomputer.com — 19.11.2025 23:59
- Sneaky2FA PhaaS kit now uses redteamers' Browser-in-the-Browser attack — www.bleepingcomputer.com — 19.11.2025 23:59