PULSE NAME
Your MFA Is No Match for Sneaky2FA
WHITE AlienVault 2025-02-28 Modified: 2025-03-30
27
IOCs
MEDIUM VOLUME
In early February 2025, the eSentire Threat Response Unit detected a user accessing a phishing site associated with Sneaky2FA, an Adversary-in-the-Middle Phishing-as-a-Service kit designed to bypass two-factor authentication. The attack involved a spam email with a link to a phishing PDF in OneDrive, redirecting users to a fake Office 365 page. Sneaky2FA uses Cloudflare Turnstile to prevent scanners from accessing the phishing page. The kit captures user credentials and 2FA codes, providing operators with session cookies for unauthorized access. Phishing operators were observed using stolen cookies to add MFA methods, hiding behind VPN and proxy services. The sophisticated nature of Sneaky2FA allows damaging follow-on activities such as email exfiltration, spam, and BEC attacks.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Sneaky2FA
Indicators of Compromise (27)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 5b049b18a1874083935bff3d8572f69c 2025-02-28
FileHash-SHA1 2acd4a7ffb26deeff5adb22635564679500a9144 2025-02-28
FileHash-SHA256 58cf64e33543791869a0f08776bcfe515fd6da36942045bed0ae0c21305442a5 2025-02-28
FileHash-SHA256 872a754101510bdc6c0f02399e44724f72922cd8066bdc8dcd75aa4b1f2e2268 2025-02-28
URL https://deepseek.exploreio.net 2025-02-28
URL https://manyanshe.com/macdownloads/script_67a654802ba053.47547911.php 2025-02-28
domain browser-storage.com 2025-02-28
domain calendly-storage.com 2025-02-28
domain chatgpt-storage.com 2025-02-28
domain deepseek-storage.com 2025-02-28
domain jobstreet-storage.com 2025-02-28
domain manyanshe.com 2025-02-28
hostname deepseek.exploreio.net 2025-02-28
hostname secure.toitoiiusa.com 2025-02-28
FileHash-MD5 5b049b18a1874083935bff3d8572f69c MD5 of 58cf64e33543791869a0f08776bcfe515fd6da36942045bed0ae0c21305442a5 2025-02-28
FileHash-SHA1 2acd4a7ffb26deeff5adb22635564679500a9144 SHA1 of 58cf64e33543791869a0f08776bcfe515fd6da36942045bed0ae0c21305442a5 2025-02-28
FileHash-SHA256 58cf64e33543791869a0f08776bcfe515fd6da36942045bed0ae0c21305442a5 2025-02-28
FileHash-SHA256 872a754101510bdc6c0f02399e44724f72922cd8066bdc8dcd75aa4b1f2e2268 2025-02-28
URL https://deepseek.exploreio.net 2025-02-28
URL https://manyanshe.com/macdownloads/script_67a654802ba053.47547911.php 2025-02-28
domain browser-storage.com 2025-02-28
domain calendly-storage.com 2025-02-28
domain chatgpt-storage.com 2025-02-28
domain deepseek-storage.com 2025-02-28
domain jobstreet-storage.com 2025-02-28
domain manyanshe.com 2025-02-28
hostname deepseek.exploreio.net 2025-02-28