CyberSecurity updates
2025-01-31 00:30:52 Pacfic

New Phishing Kit Bypasses Microsoft 365 2FA - 11d
New Phishing Kit Bypasses Microsoft 365 2FA

A new ‘Sneaky 2FA’ phishing kit is targeting Microsoft 365 accounts, using a sophisticated Adversary-in-the-Middle technique to bypass 2FA. This kit utilizes compromised WordPress sites and other domains to host phishing pages, collecting credentials and 2FA codes. The kit has been linked to the W3LL Panel OV6 phishing kit, indicating a larger threat landscape for Microsoft 365 users. The phishing method is capable of intercepting user credentials and session cookies.