BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Sneaky 2FA Phishing Kit Now Uses Browser-in-the-Browser Attack

Sneaky 2FA Phishing Kit Uses Browser-in-the-Browser and Passkey Attacks to Steal Microsoft Credentials

  • Phishing-as-a-Service (PhaaS) kit Sneaky 2FA now uses Browser-in-the-Browser (BitB) impersonation to steal Microsoft account credentials.
  • BitB creates fake browser pop-ups that simulate legitimate login windows, masking phishing URLs and enhancing deception.
  • Attackers use bot protection like Cloudflare Turnstile and conditional loading to restrict access to phishing pages and avoid detection.
  • New browser extension attacks can hijack passkey-based logins by intercepting and forging authentication keys via JavaScript injection.
  • Phishing kits also employ downgrade attacks to bypass phishing-resistant login methods such as passkeys by coercing victims to use weaker alternatives.

Malware authors behind the Phishing-as-a-Service (PhaaS) kit Sneaky 2FA have integrated Browser-in-the-Browser (BitB) technology into their phishing campaigns to capture Microsoft account credentials. This update was detailed in a report highlighting the new tactics used to enhance deception and scalability.

- Advertisement -

The BitB technique exploits HTML and CSS to create fake browser pop-ups that appear as genuine login windows but actually host embedded phishing pages. These windows display legitimate Microsoft URLs to trick victims into entering their credentials, facilitating data theft. According to Push Security, the method “masks suspicious phishing URLs by simulating a pretty normal function of in-browser authentication – a pop-up login form.”

One observed attack begins with a suspicious URL “previewdoc[.]us” that enforces bot protection using Cloudflare Turnstile. After passing the verification, users see a “Sign in with Microsoft” button to view a PDF. Clicking it opens a BitB-based phishing page where credentials and session data are harvested and sent to the attacker.

Sneaky 2FA uses obfuscation and disables developer tools to avoid analysis while quickly rotating phishing domains to limit detection. The attackers also employ conditional loading techniques to ensure only specific targets access phishing content, redirecting others to harmless sites.

Separately, researchers have uncovered attacks on passkey authentication that involve malicious browser extensions injecting JavaScript to manipulate the WebAuthn API. This passkey pwned attack generates attacker-controlled key pairs during registration and reuse them to sign authentication challenges, allowing unauthorized access to enterprise apps without needing the victim’s device or biometrics.

- Advertisement -

Furthermore, phishing kits like Tycoon carry out downgrade attacks by presenting victims with an option to use less secure login methods instead of passkeys, weakening the authentication protection. Push Security notes that the presence of weaker fallback options leaves accounts vulnerable despite passkey availability.

Users are advised to remain cautious when handling suspicious messages and browser extensions. Organizations can adopt conditional access policies to mitigate account takeover risks by blocking logins that fail to meet specific security criteria.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coldcard adds user entropy to seed generation after $112M exploit

Coinkite released firmware 5.6.1 for Coldcard Mk4/Mk5 and 1.5.1Q for Coldcard Q, requiring user-supplied...

GitLab Flaw Actively Exploited After Disclosure

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete...

PEPE Surges 25% Weekly, Outperforms Bitcoin and Ethereum

PEPE surged 14.2% in 24 hours and over 25% in the past week, outperforming...

Tom Lee: Avoid Robinhood Stock in 2026

Tom Lee of Fundstrat named Robinhood Markets Inc stock as one to avoid in...

MANTRA Token Plunges 18.5% as Chain Halts After Incident

MANTRA's native token plunged 18.5% to an all-time low of $0.004126 before the chain...

Must Read

The Best Bitcoin Casinos of 2025: An Expert’s Data-Driven Guide

Top 3 Bitcoin Casinos - Quick Comparison ...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading