Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Sneaky 2FA

1
Global rank
3 infographic chevron month
Month rank
4 infographic chevron week
Week rank

Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations.

Phishingkit
Type
Unknown
Origin
1 October, 2024
First seen
18 September, 2026
Last seen

How to analyze Sneaky 2FA with ANY.RUN

Type
Unknown
Origin
1 October, 2024
First seen
18 September, 2026
Last seen

IOCs

IP addresses
162.159.207.0
48.209.133.15
104.18.22.222
150.171.109.100
74.178.76.128
23.12.138.206
150.171.28.11
135.232.92.97
128.24.231.64
20.23.115.113
66.179.210.151
48.209.138.189
74.125.250.129
23.216.77.19
23.59.18.102
150.171.27.11
2.16.241.201
142.251.14.113
150.171.22.17
23.197.136.177
Hashes
db39694c444ea393569aafb2cd8ec865006f3df9ecbcb7996e7b219b30ec366d
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
35872a3343d4b4768fe4702a8dc18b749933e81210db13466ad172bd2880f6eb
de6d7b7c2427ec4e738407d7834b71941f69166b030355e00f325ff1391df5a1
Domains
stun.l.google.com
edge.microsoft.com
stun.cloudflare.com
settings-win.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
config.edge.skype.com
stun1.l.google.com
arc.msn.com
login.live.com
edge-consumer-static.azureedge.net
clients2.googleusercontent.com
activation-v2.sls.microsoft.com
crl.microsoft.com
go.microsoft.com
update.googleapis.com
api.edgeoffer.microsoft.com
self.events.data.microsoft.com
pservicessinc.pservicessinc.com
slscr.update.microsoft.com
code.jquery.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
https://copilot.microsoft.com/c/api/user/eligibility
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:eyxa0lyvzdulvrun-lwwpghvdoto2gjoobe3j44ntiy&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://pservicessinc.pservicessinc.com/b64.php
https://pservicessinc.pservicessinc.com/$sybo$zgvhbmeuaglja21hbkbzdxblcmlvcmvuzxjnes5jb20=
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/autofillservice/core/page/-4330353758434402083/-3790914475600810104?cidalgoversion=2
https://challenges.cloudflare.com/turnstile/v0/api.js
https://challenges.cloudflare.com/turnstile/v0/g/330e41bb475c/api.js
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/f/av0/rch/t5yfq/0x4aaaaaaegvnsckeutnapnt/auto/fbe/new/normal?lang=auto
https://pservicessinc.pservicessinc.com/4d02ffe933c8abbc/images/default.png
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/fo/2341210978:1789700710:j3vvztodxupb06sox72g3nb42cqdv4n2u2ae7fa76ng/a3cd41c6ff35b500/ilounbw6r30fa0ieerpe0nw2f4pp9u3epk.cqnic6ms-1789702068-1.2.1.1-6uv2vyywmdtvj6m1re9nmao5zf27hk00eikcwnjrvqe2yrjjhapbqlo1kjuekt9s
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/a3cd41c6ff35b500/1789702068704/e13caad767b20b6cbc2fff699158377698197de3e7d88393dadf31d94c6236d4/wawbpssz025mu.1dun81dtehqk4woh5nkoj3u.ri5bk-1789702068-1.3.1.1-f7fsiimmiecmzl2zxwvghcgembpt6doc6hc2_3nqyojegrf.czi6pqix43vcx2cyw9_xspkezkaweevzhjxacmisjzgg5jl5oawsicqjr61fl5fre42mml2d5qxfgo3cpjgsadfunnk_nuh8tnhsyawnncpfx1murpajlz6ulgsqnyof3k219mawr74oz3fr1rdhmoe7i.jxegb5gwicuw5bq2tfszczrlp7d7t8lfaubsxhv0mek0tmopmrdtmc9i7uw0gfrwqgei3qab.jtivfg2ue9wdymhrfmdvl6x.ab5e3ayztqgnps3lcsnomls1a6wazdhencv1md3k.5dbhjc4rtlpthyzofybw4bfbngsiyeynut.ysyclbei2lrfwuwpzucalfzkkpapklfbqatphj.sl.hv0txyzrehdowho4i4jdwi7jaqmvcayh7lyizom1avfnkqxsm8.rg8z.qzgazxzikgpp_suagpboauwvuntnzbae6zptmp8jxoq72gdjq2csj8iy_ia0cn1hq0rjq8h4qxijzptqpate.sv2_lehzc0mtf_ykcwlhd7f2apbemutpoo9i483lf2a_gm6y9zcxoypuy4n_st9yv1qmlm4bsd4o3xitrky3hzuhpfkfcsv90bjhu4cdncaokuu_polytooiei10qeltlwvvreaan7fg7g0gjvreyiatmij_yldgoqsbfigvhsljbrkpf7fettb__ku5dpus3hwvrzbcv14tcvo5mvknttfpp2mhpnineecyd.okfinumckdxomsby0xwicp0pi5qsxzqw6nc6mz2qvmla
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/ci/a3cd41c6ff35b500/1789702068706/nee8paftteyplabzjmgwtdinx27jmwpbxe1mgqft0.0-1789702068-1.3.1.1-5nil9ui0i6ajvva3gisgc_xmymh3nsx5zbjul.smu_c4rvogixnstbyfqfcwoq.h4_7ljz.qtcpk4ixpsm_ajvpyebo4lm0ajcsd614kkyjws29sexd3nu6n.a7mjptswgn6osiutth84swickpezopyyvw_zr2r62z6dsm2dcnsfoj0wv8ew5eo0ane5ypb6hqbtfdbfu.f8kn0yc8uh7nbtydb33v8inuztp775n2b05v5xvwcarn8.6s2wsh8qa0jmjc4zgpardplgsta9ikaa7igugmgm0e7oqzl5qhlex1d8v3sj5pwqo4mn.9exrpjlgrrt9lfrtqipdjka2ulhvnnlfw8s8qlwxfdmd8f4rwupcdeldq3kmqf1zt.jslj4vqs0kjioaisyzfdtuot5bipwvl5d7k6clim7t6jsue8rp2srqfhwbrvpqmy_ul7eruymz5qrynbamxkc3bjq8r2x3y7j9dthgihxpn4sejozuhckbb44bb67yc4xrl9v55fioied_sohmggmlwfubynhvuyrd4shl.2incj6fdilnwgqzhui1yuvztqdk6bdhes5m7aghz.fkiqqkk4m.bi4odtzcqlpqvzhjy_dsdfao3r8abe.lfa0wjcmxe4fwg.s0lzjauerlyzfoqkgfhz6zckktl1nequvf9rwdu_la2aysmef_yzpgazdrnox9b0pv_t339nqqokj2xesclhao5lpy0qfgbyi54
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d273%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1292
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1586
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3183
comments 0

What is Sneaky 2FA malware?

Sneaky 2FA phishing kit is a malware strain designed to bypass two-factor authentication (2FA), a critical security layer used by individuals and organizations worldwide. By hijacking authentication processes in real-time, this malware undermines what many consider a key safeguard in modern cybersecurity.

It often works as part of a larger attack chain, coordinating with infostealers, remote access trojans (RATs), and phishing kits. Its modular architecture, stealth capabilities, and real-time data interception make it a significant threat in today’s digital landscape.

First detected in October 2024, it is a full-featured phishing kit that compromises Microsoft 365 accounts. Sold via a Telegram-based PhaaS model, it provides cybercriminals with obfuscated source code for independent deployment.

Sneaky 2FA employs advanced anti-bot and anti-analysis measures, such as Cloudflare Turnstile challenges and IP filtering, to evade detection. Its fake Microsoft authentication pages, complete with auto-filled email fields and blurred legitimate interface screenshots, create a convincing illusion of authenticity. Nearly 100 domains hosting Sneaky 2FA phishing pages have been identified.

Sneaky 2FA propagates through multiple distribution channels, leveraging both technical and social engineering techniques:

  • Phishing email campaigns have been observed sending email with pseudo payment receipts to make users open bogus PDF documents containing a QR code that redirects them to a malicious site.
  • Attackers embed QR codes in seemingly legitimate documents, which redirect users to phishing sites when scanned with mobile devices.
  • Campaigns often use urgent or compelling subject lines related to account security, payment notifications, or business-critical communications to encourage immediate action.
  • Attackers may compromise legitimate websites to host phishing pages, lending credibility to malicious content.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

What Sneaky 2FA Can Do to Your Device

Sneaky 2FA's impact extends beyond simple credential theft. Once attackers gain access to Microsoft 365 accounts, they can perform:

  • Session Hijacking: Steal active authentication sessions, allowing immediate access to user accounts without triggering additional security prompts

  • Persistent Access: Maintain long-term access to compromised accounts through stolen authentication tokens

  • Data Exfiltration: Access and download sensitive emails, documents, and organizational data stored in Microsoft 365 services

  • Account Takeover: Gain complete control over user accounts, including the ability to change passwords and security settings

  • Lateral Movement: Use compromised accounts as stepping-stones to access other systems and accounts within the organization

    How Sneaky 2FA Threatens Businesses and Organizations

Sneaky 2FA poses severe risks to businesses, particularly those reliant on Microsoft 365 for operations:

  • Business Email Compromise (BEC) and Financial Losses: Attackers can use compromised executive accounts to initiate fraudulent wire transfers or manipulate business transactions. Sneaky 2FA falls under the class of business email compromise attacks.
  • Data Breaches: Exposure of key corporate data, including customer info, financial records, and strategic plans, leading to business failures, regulatory fines, and reputational damage.
  • Operational Disruption: Compromised accounts can disrupt workflows, especially in critical infrastructure sectors.
  • Supply Chain Attacks: Attackers can use hijacked accounts to target partners or clients, amplifying the impact.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

How Does Sneaky 2FA Function?

Sneaky 2FA doesn't directly compromise individual computers but rather targets cloud-based accounts and services. The attack starts when users receive phishing emails containing links or QR codes that appear to be from Microsoft or other trusted sources.

After clicking malicious links, they are directed to convincing replicas of Microsoft 365 login pages hosted on attacker-controlled infrastructure. Sneaky 2FA as an adversary-in-the-middle intercepts information sent between a device with Microsoft 365 and a phishing server.

Even when users complete legitimate two-factor verification, the system captures and stores authentication tokens that can be replayed to gain account access. With valid session tokens, attackers can access Microsoft 365 accounts without triggering additional security prompts, effectively bypassing multi-factor authentication.

Samples of Sneaky2FA in action can be observed in ANY.RUN's Interactive Sandbox where the whole attack chain is dissected in a safe virtual machine environment.

Watch an analysis session of Sneaky 2FA fresh sample

Sneaky 2FA analysis in Interactive Sandbox Sneaky 2FA analysis in ANY.RUN Interactive Sandbox

The attack unfolds through a carefully orchestrated series of steps designed to bypass two-factor authentication on Microsoft 365 accounts.

When a victim receives a phishing email, it typically appears as a legitimate security alert or notification from Microsoft 365, encouraging them to click a link. This link may contain an "autograb" feature that pre-fills the victim’s email address on the fake login page, increasing the illusion of authenticity.

Upon clicking the link, the victim encounters first a fake 'Access document' or other lure and then is redirected to a Cloudflare CAPTCHA designed to verify that they are human and to filter out automated bots, proxies, VPNs, or suspicious IP addresses and automated sandboxes without ML recognition. ANY.RUN has Automated interactivity (ML) which will click CAPTCHA. Visitors flagged as bots or researchers are redirected to harmless pages, such as a Wikipedia article, to avoid raising suspicion.

Once the victim passes the challenge, they are presented with a highly realistic fake Microsoft 365 login page, complete with blurred background images taken from actual Microsoft sites to enhance credibility. The victim enters their password, which is immediately captured by the phishing server. The kit then detects the victim’s configured 2FA method and prompts for the second authentication factor.

Acting as an adversary-in-the-middle, the phishing kit captures the 2FA code in real time as the victim submits it. With this information, the attackers hijack the session cookies, effectively bypassing the need for the 2FA code in subsequent accesses and gaining full control over the victim’s Microsoft 365 account.

If user submits URL or a file through API Throughout this process, the Sneaky 2FA kit employs multiple anti-detection techniques, including obfuscation of HTML and JavaScript code (tag obfuscated-js), embedding junk data and base64-encoded images, and using anti-debugging measures to thwart analysis via browser developer tools. The kit’s traffic filtering mechanisms ensure that only genuine targets are exposed to the phishing pages, minimizing the risk of detection by security researchers or automated defenses.

Gathering Threat Intelligence on Sneaky 2FA Malware

Threat intelligence plays a crucial role in defending against Sneaky 2FA and phishing kits in general by providing actionable data about attack patterns, indicators of compromise, and emerging threats. Indicators of Compromise enable proactive blocking of phishing infrastructure, and understanding Sneaky 2FA’s tactics, techniques, and procedures informs detection rules.

Start from searching Sneaky 2FA by the threat name in ANY.RUN Threat Intelligence Lookup:

threatName:"Sneaky2FA"

Sneaky 2FA in TI Lookup Sneaky 2FA sandbox analyses found via ANY.RUN TI Lookup

Extract IOCs from analysis sessions and come back to TI Lookup to research them, enrich them with context, and find associated indicators.

Sneaky 2FA IOCs in the Sandbox Sneaky 2FA IOCs from a sandbox analysis

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Sneaky 2FA illustrates the evolution of phishing attacks, demonstrating how cybercriminals continue to adapt their tactics to bypass increasingly sophisticated security measures. The threat's ability to circumvent two-factor authentication through adversary-in-the-middle techniques highlights the limitations of traditional security approaches and the need for more comprehensive protection strategies. The combination of technical controls, user education, and threat intelligence provides the best defense against this evolving threat landscape.

Gather actionable intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More
WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More
Phantom Stealer screenshot
Phantom Stealer
phantomstealer
Phantom Stealer is a commercially available Malware-as-a-Service infostealer targeting Windows systems. It harvests browser passwords, session cookies, payment data, cryptocurrency wallets, system information, screenshots, and application data.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
Grandoreiro screenshot
Grandoreiro
grandoreiro
Grandoreiro is a Latin American banking trojan first observed in 2016. It targets mostly Spanish-speaking countries, such as Brazil, Spain, Mexico and Peru. This malware is operated as a Malware-as-a-Service (MaaS), which makes it easily accessible for cybercriminals. Besides, it uses advanced techniques to evade detection.
Read More