Sneaky2FA Attack Toolkit Upgrades Browser-in-the-Browser Techniques to Steal Microsoft 365 Accounts More Convincingly
480/68 Friday, November 21, 2025 A recent report from Push Security reveals that the Phishing-as-a-Service (PhaaS) toolkit known as Sneaky2FA has enhanced its capabilities by integrating Browser-in-the-Browser (BitB) techniques. This upgrade allows attackers to steal Microsoft 365 login credentials and session tokens with a high degree of realism. The BitB method enables the toolkit to […]
