Sneaky2FA ecosystem shift changes threat-actor operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
Sneaky2FA has added browser-in-the-browser (BitB) lures to its phishing service, increasing its ability to steal Microsoft credentials and active sessions. The new fake Microsoft pop-up makes the existing attacker-in-the-middle (AitM) theft flow more convincing for Microsoft 365 users. The upgrade is paired with conditional loading and obfuscation, which can make the service harder to detect and block.
Related Happenings
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Microsoft Entra OAuth Client ID spoofing campaign
Campaign
H score58
First: 13.07.2026 16:00
Last: 13.07.2026 16:00
Sources 1
About this happening:
A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft Entra OAuth Client ID spoofing campaign
CampaignAbout this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
Campaign
H score37
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
CampaignAbout this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
Timeline
-
19.11.2025 23:59 2 articles · 7mo ago
Sneaky2FA adds BitB Microsoft login lures
Initial DisclosureSneaky2FA added browser-in-the-browser (BitB) pop-ups that mimic a legitimate Microsoft login window and are used with its existing attacker-in-the-middle (AitM) flow to steal Microsoft credentials and active session tokens from Microsoft 365 accounts. The phishing pages also use conditional loading and heavily obfuscated HTML/JavaScript to reduce detection, while victims are steered through previewdoc[.]com and a Cloudflare Turnstile check before the fake Microsoft sign-in appears.
Show sources
- Sneaky2FA PhaaS kit now uses redteamers' Browser-in-the-Browser attack — www.bleepingcomputer.com — 19.11.2025 23:59
- Sneaky2FA PhaaS kit now uses redteamers' Browser-in-the-Browser attack — www.bleepingcomputer.com — 19.11.2025 23:59