New Phishing Kit Using BitB Technique Targets Users to Steal Microsoft Account Credentials via Sneaky 2FA Attacks

Security researchers have identified a new evolution in the Sneaky2FA Phishing-as-a-Service (PhaaS) kit, which now integrates the Browser-in-the-Browser (BitB) phishing technique to steal Microsoft account credentials.

This kit, distributed via a Telegram-controlled bot, gives cybercriminals access to a licensed, obfuscated version of the source code, making it easy to deploy independently while retaining consistent code signatures for tracking.

Push Security analysts observed active campaigns hosted on previewdoc[.]us, where visitors are first prompted to complete a Cloudflare Turnstile verification before loading the phishing page.

Once cleared, users are redirected to a prompt that appears to be an Adobe Acrobat Reader document, with a “Sign in with Microsoft” button. Clicking it triggers a fake Microsoft login form rendered inside an embedded BitB pop-up window designed to appear legitimate.

The phishing pop-up automatically adapts to the victim’s operating system and browser, mimicking Microsoft’s legitimate sign-in interface while masking the actual URL behind a simulated address bar.

Once credentials and MFA tokens are entered, attackers capture them in real time, enabling complete account takeover.

Advanced Detection Evasion and Obfuscation Tactics

Unlike traditional Attacker-in-the-Middle (AiTM) kits, Sneaky2FA’s BitB variant employs multiple obfuscation and anti-analysis layers to evade automated scanning tools and threat crawlers.

The kit employs bot-protection technologies like CAPTCHA and Cloudflare Turnstile to block web crawlers, conditional loading to redirect unwanted IPs (including security vendors) to benign pages, and anti-sandbox measures that disable browser developer tools during analysis.

BitB Phishing Kit
BitB Phishing Kit

Its HTML and JavaScript code are heavily obfuscated, often breaking up interface text with invisible HTML tags and embedding assets as encoded images rather than using plain-text techniques, designed to undermine pattern detection and static scanning.

Sneaky2FA campaigns also leverage domain rotation and URL masking, using long, randomized paths on compromised or abandoned domains that remain live for only a short time. This “burn-and-replace” method weakens defenses that depend on domain reputation.

Researchers caution that Sneaky2FA’s adoption of BitB phishing aligns with a broader PhaaS trend, also seen in Raccoon0365’s “BitB mini-panel.” These developments highlight how PhaaS operators are weaponizing sophisticated MFA-bypass capabilities once reserved for advanced threat actors.

Push Security confirmed that its detection systems successfully identified the Sneaky2FA BitB kit in real time, blocking the phishing attempt before users could be compromised.

As attackers innovate within the PhaaS ecosystem, this new wave of BitB-enabled phishing demonstrates how social engineering and technical deception continue to evolve faster than traditional security controls.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories