PULSE NAME
Sneaky 2FA Phishing Kit Targeting Microsoft 365 Accounts
WHITE Superpro 2025-01-18 Modified: 2025-02-17
111
IOCs
HIGH VOLUME
Cybersecurity researchers have uncovered a new Adversary-in-the-Middle (AitM) phishing kit named Sneaky 2FA, designed to steal Microsoft 365 credentials and two-factor authentication (2FA) codes. French cybersecurity firm Sekoia identified the kit, active since October 2024, and discovered nearly 100 domains hosting related phishing pages. The phishing kit includes references to W3LL Store, a known phishing syndicate behind the W3LL Panel, raising suspicions that Sneaky 2FA is based on similar technology. Some domains linked to Sneaky 2FA were previously tied to older AitM kits like Evilginx2 and Greatness, indicating a shift among cybercriminals to the newer service. Campaigns leveraging Sneaky 2FA use QR codes embedded in fake payment receipt emails to lure victims. These codes redirect users to phishing pages to harvest credentials and bypass 2FA protections.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
OV6 PlugX
Indicators of Compromise (111)
All URL FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL https://highnationservices.com/n/#victim@example.com 2025-01-18
URL https://highnationservices.com/n/uswDOVS70y9sjyPwtLieCJdZiEUGhokxRUvY7JApYlFo35Sb9o66AvhK8oNrHPTgj9aaJDHItTWDnPOo3t4mz8Tfhf7GBem0YE1cqx8O13VoKuWIbN4knGg6fRrvMIZXRQ2xgdEFzj2mVBzwSbpe5c/validate 2025-01-18
FileHash-SHA256 5d91563b6acd54468ae282083cf9ee3d2c9b2daa45a8de9cb661c2195b9f6cbf 2025-01-18
FileHash-SHA256 8c4e78b1bc0a0923fccc0cd2d7ca06023b6ab15af079e6b19d7d5d2fddc5488d 2025-01-18
URL http://128.0.0.0 2025-01-18
URL http://129.0.0.0 2025-01-18
URL http://185.125.100.81/api/key 2025-01-18
URL https://b.leadbi.com/l/44e234ab-9118-47ed-a1a1-ca66f913c271.html?next=https://highnationservices.com/n/#victim@example.com 2025-01-18
URL https://kagumigroup.id/wp-content/plugins/well/auth/j9P8KGpfDZyoHplo5XdnHOw79OCkDYo2l7TQcrrnclSz2XGLzmtCghFJwIWR1AaW33Rk36Z0ymZc6DIgMy4EFqTsiiqAKEBIN5jiTbYAUk1BfG4uoVhetLa2XWebUSShQOFq7L8Mpx1vf4Pum0xBVx/verify 2025-01-18
URL https://mysilverfox.com.my/00/#victim@example.com 2025-01-18
URL https://mysilverfox.com.my/00/7N0tV3XAh1yp4NFo9X6YsH3cOam6DYJhmMEXRky24mzGUuTE2RpwIIlI4olBypVCEYqiKFPDTAsRvKrS8bgiKBOZiPOUnxoCSHveA0zk5hcdjQ1UltSxdw7rdgZoo7HDWorfj9CzN8gc0q5PQ19nZe/index 2025-01-18
URL https://sneakylog.store/api/key 2025-01-18
URL https://trac-labs.com/wikikit-aitm-phishing-kit-where-links-tell-lies-abdea71ba094 2025-01-18
domain africanagrirnarket.com 2025-01-18
domain alliedhealthcaresolution.com 2025-01-18
domain allorganichome.com 2025-01-18
domain allorganicitems.com 2025-01-18
domain allorginichomes.xyz 2025-01-18
domain apppowerappsportals.top 2025-01-18
domain auxin.co.in 2025-01-18
domain aweitapp.com 2025-01-18
domain baptihealth.com 2025-01-18
domain bhlergroup.com 2025-01-18
domain carpetcleaningmanitoba.ca 2025-01-18
domain cchosting.co.za 2025-01-18
domain claytoncontsruction.net 2025-01-18
domain cnphys.com 2025-01-18
domain coysem.com 2025-01-18
domain desirenetwork.in 2025-01-18
domain docsafybeifur2mabbggrihscauthenticnotes.online 2025-01-18
domain docuinshare.top 2025-01-18
domain dolh6growth.online 2025-01-18
domain drgoelsdmd.com 2025-01-18
domain drop-project.top 2025-01-18
domain emailsay.com 2025-01-18
domain emea-nec.com 2025-01-18
domain erhakalip.com 2025-01-18
domain eto1908.org 2025-01-18
domain files42.com 2025-01-18
domain florenceorganics.us 2025-01-18
domain forcainvicta.com.br 2025-01-18
domain funnelflex.co 2025-01-18
domain glamorouslengths.su 2025-01-18
domain globalservicesqtr.com 2025-01-18
domain greyscaleal.com 2025-01-18
domain guardiansresearch.org 2025-01-18
domain highnationservices.com 2025-01-18
domain historischeverenigingmarum.online 2025-01-18
domain intertrustsgroup.com 2025-01-18
domain iziloyer.com 2025-01-18
domain kagumigroup.id 2025-01-18
domain leanstartupatelier.co 2025-01-18
domain lovencareurology.in 2025-01-18
domain matcocomponent.com 2025-01-18
domain may-april.com 2025-01-18
domain meliorahospital.com 2025-01-18
domain metin2odisey.com 2025-01-18
domain ms-consulting-dom.fr 2025-01-18
domain mscserv.com 2025-01-18
domain mysilverfox.com.my 2025-01-18
domain nashnights.com 2025-01-18
domain oempcworlds.org 2025-01-18
domain ohconnects.org 2025-01-18
domain omnirayoprah.cfd 2025-01-18
domain organichoicehome.com 2025-01-18
domain outsourcel.com.au 2025-01-18
domain pipaltree.ngo 2025-01-18
domain portalpowerfiles.top 2025-01-18
domain portalpowerstorages.top 2025-01-18
domain powa.co.zw 2025-01-18
domain printserve.co.ke 2025-01-18
domain profitminers.in 2025-01-18
domain reintergestna.org 2025-01-18
domain reliant-rehabs.com 2025-01-18
domain rockandrevenue.com 2025-01-18
domain rurrasqueamos.click 2025-01-18
domain senangwasap.com 2025-01-18
domain snatched-beautybar.com 2025-01-18
domain sneakylog.store 2025-01-18
domain stillmanconsulting.net 2025-01-18
domain storageorder.sbs 2025-01-18
domain sukrajclasses.com 2025-01-18
domain sysarchirnc.com 2025-01-18
domain tesla-apply-job.com 2025-01-18
domain thewoodlandretreat.in 2025-01-18
domain thumenectrics.es 2025-01-18
domain trac-labs.com 2025-01-18
domain tvsyndciate.com 2025-01-18
domain unalkardesler.net 2025-01-18
domain urbanumbrella.org 2025-01-18
domain usfightingsystems.com 2025-01-18
domain vlsbali.com 2025-01-18
domain w3ll.store 2025-01-18
domain webitww.com 2025-01-18
domain welcomehomeproject.org 2025-01-18
domain windstreaim.com 2025-01-18
domain wordtex.com 2025-01-18
domain wwgle.com 2025-01-18
domain yaharaho.com 2025-01-18
domain yogatrapezepoint.com 2025-01-18
domain yugaljeeautomotive.com 2025-01-18
domain yushengusa.com 2025-01-18
hostname b.leadbi.com 2025-01-18
hostname hsrcxeeae.mypi.co 2025-01-18
hostname loginoffice365commonauth00000365user1153196333.empreendendocomgrafica.com 2025-01-18
hostname loginoffice365commonauth00000365user6867620079.empreendendocomgrafica.com 2025-01-18
hostname o7t5dgbx-staging.dreamwp.com 2025-01-18
hostname office365.context.correlation.id 2025-01-18
hostname ol.advanceplastics-ke.com 2025-01-18
hostname www.fabribat.com 2025-01-18
hostname www.northernaid.org 2025-01-18