Sneaky 2FA BitB phishing activity
Malware Activity
Summary
Hide ▲
Show ▼
The Sneaky 2FA phishing kit has added Browser-in-the-Browser (BitB) pop-ups, making credential theft and Microsoft account takeover easier at scale. Attack chains can start from suspicious URLs such as previewdoc[.]us, where users first face Cloudflare Turnstile checks before being sent to a fake sign-in flow. The fake browser window can show a legitimate-looking Microsoft URL while the victim enters credentials into a phishing page. The same flow can also steal session details, enabling full account takeover.
Related Happenings
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
GPPStorm Google Partners enrollment phishing campaign
Campaign
H score33
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
GPPStorm Google Partners enrollment phishing campaign
CampaignAbout this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...
Microsoft Entra OAuth Client ID spoofing campaign
Campaign
H score58
First: 13.07.2026 16:00
Last: 13.07.2026 16:00
Sources 1
About this happening:
A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft Entra OAuth Client ID spoofing campaign
CampaignAbout this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Timeline
-
18.11.2025 20:31 2 articles · 7mo ago
Sneaky 2FA adds BitB phishing pop-ups
Initial DisclosureResearchers observed the Sneaky 2FA Phishing-as-a-Service kit using Browser-in-the-Browser (BitB) pop-ups to imitate Microsoft sign-in prompts, including a flow that sent users from previewdoc[.]us through Cloudflare Turnstile checks before loading a fake Microsoft login page. The phishing page could exfiltrate entered credentials and session details, while the operators also used obfuscation, disabled browser developer tools, conditional loading, and fast domain rotation to reduce analysis and detection.
Show sources
- Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar — thehackernews.com — 18.11.2025 20:31
- Sneaky2FA PhaaS kit now uses redteamers' Browser-in-the-Browser attack — www.bleepingcomputer.com — 19.11.2025 23:59