BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Sneaky 2FA Phishing Kit Now Uses Browser-in-the-Browser Attack

Sneaky 2FA Phishing Kit Uses Browser-in-the-Browser and Passkey Attacks to Steal Microsoft Credentials

  • Phishing-as-a-Service (PhaaS) kit Sneaky 2FA now uses Browser-in-the-Browser (BitB) impersonation to steal Microsoft account credentials.
  • BitB creates fake browser pop-ups that simulate legitimate login windows, masking phishing URLs and enhancing deception.
  • Attackers use bot protection like Cloudflare Turnstile and conditional loading to restrict access to phishing pages and avoid detection.
  • New browser extension attacks can hijack passkey-based logins by intercepting and forging authentication keys via JavaScript injection.
  • Phishing kits also employ downgrade attacks to bypass phishing-resistant login methods such as passkeys by coercing victims to use weaker alternatives.

Malware authors behind the Phishing-as-a-Service (PhaaS) kit Sneaky 2FA have integrated Browser-in-the-Browser (BitB) technology into their phishing campaigns to capture Microsoft account credentials. This update was detailed in a report highlighting the new tactics used to enhance deception and scalability.

- Advertisement -

The BitB technique exploits HTML and CSS to create fake browser pop-ups that appear as genuine login windows but actually host embedded phishing pages. These windows display legitimate Microsoft URLs to trick victims into entering their credentials, facilitating data theft. According to Push Security, the method “masks suspicious phishing URLs by simulating a pretty normal function of in-browser authentication – a pop-up login form.”

One observed attack begins with a suspicious URL “previewdoc[.]us” that enforces bot protection using Cloudflare Turnstile. After passing the verification, users see a “Sign in with Microsoft” button to view a PDF. Clicking it opens a BitB-based phishing page where credentials and session data are harvested and sent to the attacker.

Sneaky 2FA uses obfuscation and disables developer tools to avoid analysis while quickly rotating phishing domains to limit detection. The attackers also employ conditional loading techniques to ensure only specific targets access phishing content, redirecting others to harmless sites.

Separately, researchers have uncovered attacks on passkey authentication that involve malicious browser extensions injecting JavaScript to manipulate the WebAuthn API. This passkey pwned attack generates attacker-controlled key pairs during registration and reuse them to sign authentication challenges, allowing unauthorized access to enterprise apps without needing the victim’s device or biometrics.

- Advertisement -

Furthermore, phishing kits like Tycoon carry out downgrade attacks by presenting victims with an option to use less secure login methods instead of passkeys, weakening the authentication protection. Push Security notes that the presence of weaker fallback options leaves accounts vulnerable despite passkey availability.

Users are advised to remain cautious when handling suspicious messages and browser extensions. Organizations can adopt conditional access policies to mitigate account takeover risks by blocking logins that fail to meet specific security criteria.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Sonic V2.2 doubles smart contract size limits for developers

Sonic V2.2 doubles the maximum deployed contract size from 24 KiB to 48 KiB...

ByteDance Secures $29.6B Loan from 30 Banks for AI Push

TikTok parent ByteDance secured a $29.6 billion loan from nearly 30 Chinese and international...

Musk: Tesla IPO value was a thousandth of current value

Tesla stock fell roughly 6% on Friday after the Cybercab launch event in Austin...

Tesla Cybercab stock crashes 6% on NHTSA audit

Tesla stock dropped 6% in an hour after the NHTSA opened a compliance audit...

Pineapple moves $1B mortgage records onto Injective blockchain

Pineapple Financial has migrated over $1 billion in residential mortgage records onto Injective, with...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading