Sneaky 2FA Phishing Kit Uses Fake Browser Windows To Capture MFA Codes

Flat illustration of a laptop computer screen displaying a dialog box or window with blank fields, represented by white rectangles, and a yellow cursor arrow pointing at one of the fields, suggesting user input or interaction with a software interface or online form on an orange background.

Researchers at Malwarebytes have analyzed a phishing as a service kit known as Sneaky 2FA. The tool is designed to steal both account credentials and multi-factor authentication codes by imitating single sign on windows inside a web page. The kit uses a browser in the browser technique in which a realistic looking login window is rendered within the page so that it appears to be a separate browser pop up.

According to Malwarebytes, customers who buy access to the kit receive obfuscated code that they can deploy on phishing sites. When a victim visits such a site, it can display a fake login window that mimics the appearance of a well known identity provider. This includes visual elements such as window controls and a simulated address bar. Behind the scenes, the kit proxies traffic to the genuine sign in page while capturing any usernames, passwords, and time based one time codes that the victim enters.

The analysis indicates that the kit includes management features for attackers to view and organize stolen credentials. Its authors are actively updating it. Malwarebytes reports that Sneaky 2FA is being marketed in criminal channels and that its functionality lowers the technical barrier for actors who want to bypass basic MFA protections without building their own man in the middle infrastructure.

Malwarebytes notes that this style of attack can defeat common two factor systems that rely on short lived codes sent by SMS, generated in an authenticator app, or delivered by email. This is because the attacker collects the code in real time and can replay it to the real service. The company recommends moving to phishing resistant authentication methods such as FIDO based security keys or passkeys that are cryptographically bound to a specific origin. It also advises organizations to train users to verify the true browser address bar before entering credentials.

Sources: Malwarebytes; The Hacker News.

By the ID Tech Editorial Team