PULSE NAME
Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
WHITE Sneaky Log AlienVault 2025-01-17 Modified: 2025-02-16
24
IOCs
MEDIUM VOLUME
A new Adversary-in-the-Middle (AiTM) phishing kit called Sneaky 2FA has been discovered targeting Microsoft 365 accounts. The kit is sold as Phishing-as-a-Service by a cybercrime service called Sneaky Log, which operates via a Telegram bot. Sneaky 2FA uses anti-bot and anti-analysis features, authenticates with Microsoft APIs, and employs various obfuscation techniques. The phishing pages are typically hosted on compromised WordPress sites or attacker-controlled domains. The kit appears to be based on the W3LL OV6 phishing kit codebase. Sneaky Log's operations include selling tools like the AiTM phishing kit, an email sender, and redirect/attachment services. The service uses multiple cryptocurrencies for payments and may employ transaction obfuscation mechanisms.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Sneaky 2FA
Indicators of Compromise (24)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain africanagrirnarket.com 2025-01-17
domain alliedhealthcaresolution.com 2025-01-17
domain allorganicitems.com 2025-01-17
domain allorginichomes.xyz 2025-01-17
domain apppowerappsportals.top 2025-01-17
domain baptihealth.com 2025-01-17
domain bhlergroup.com 2025-01-17
domain claytoncontsruction.net 2025-01-17
domain desirenetwork.in 2025-01-17
domain docuinshare.top 2025-01-17
domain dolh6growth.online 2025-01-17
domain drop-project.top 2025-01-17
domain emea-nec.com 2025-01-17
domain files42.com 2025-01-17
domain florenceorganics.us 2025-01-17
domain glamorouslengths.su 2025-01-17
domain docsafybeifur2mabbggrihscauthenticnotes.online 2025-01-17
domain greyscaleal.com 2025-01-17
domain guardiansresearch.org 2025-01-17
hostname hsrcxeeae.mypi.co 2025-01-17
domain intertrustsgroup.com 2025-01-17
domain lovencareurology.in 2025-01-17
domain sneakylog.store 2025-01-17
domain tesla-apply-job.com 2025-01-17