Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials and Session Tokens — Threadlinqs Intelligence
As of 2026-08-05, Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials and Session Tokens is a high-severity threat intel threat attributed to Sneaky Log, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1888 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Sneaky Log · FINANCIAL
Three distinct Phishing-as-a-Service (PhaaS) kits — Sneaky 2FA (AiTM reverse-relay, ~$200/mo, 100+ domains since Oct 2024), EvilTokens (OAuth Device Code abuse, 340+ M365 orgs across 7+ countries
Three commercially available Phishing-as-a-Service (PhaaS) kits are actively targeting US organizations to compromise Microsoft 365 accounts by bypassing multi-factor authentication through fundamentally different technical approaches. Together they represent a structured escalation in the phishing-as-a-service ecosystem, each refining a distinct MFA-bypass technique into a turnkey product.
Sneaky 2FA (operated by 'Sneaky Log' via @SneakyLog_bot on Telegram, ~$200/month) employs an Adversary-in-the-Middle reverse-relay architecture. The victim clicks a phishing link or scans a QR code from a PDF attachment, passes through a Cloudflare Turnstile gate and IP-filtering layer, and lands on a cloned M365 login page. Credentials are POSTed to the phishing server, which relays them live to Microsoft's API. The victim completes real MFA against Microsoft's backend, and the session cookie is captured server-side. The kit rotates User-Agent strings across authentication steps (e.g., Safari-on-iOS for login, Chrome-on-Windows for MFA), enabling the 'impossible device shift' detection signature. First observed in October 2024 and formally disclosed by Sekoia in December 2024, the kit reuses source code from the W3LL OV6 AiTM kit (Group-IB, 2023). By early January 2025, over 100 Sneaky 2FA domains had been identified. In 2025, the kit added Browser-in-the-Browser (BITB) functionality per CSO Online reporting, and has been observed using trusted sender abuse, route polymorphism, and M365 replay attacks per ZeroBEC research. The operator infrastructure includes license-validation servers at sneakylog[.]store and 185.125.100[.]81, with cryptocurrency payments (BTC, USDT-TRC20, ETH, LTC) laundered through a third-party mixing service.
EvilTokens (first observed mid-February 2026, disclosed by Sekoia in March 2026) pioneers a fundamentally different approach: it never presents a fake login page or captures a password. Instead it weaponizes the OAuth 2.0 Device Authorization Grant flow — designed for keyboardless devices — against Microsoft 365. The attacker requests a device code from Microsoft's legitimate OAuth endpoint, then tricks the victim into entering the code at microsoft.com/devicelogin. The victim completes normal sign-in including MFA, and Microsoft issues access and refresh tokens directly to the attacker's already-polling client. The kit features dynamic code generation (the 15-minute timer starts only when the victim lands on the page), AI-generated hyper-personalized lures, and a backend API that converts refresh tokens to Primary Refresh Tokens (PRTs) for persistent access. The infrastructure spans thousands of Railway.com polling nodes, Cloudflare Workers, Vercel, and AWS Lambda, with the X-Antibot-Token custom HTTP header used for backend authentication. Over 340 M365 organizations across 7+ countries have been compromised since mid-February 2026. Post-compromise capabilities include 7 parallel Graph API reconnaissance queries, Azure resource enumeration, OWA session cookie generation, and automated inbox rule creation for BEC fraud. The kit is assessed by Sekoia as 'the first PhaaS to offer turnkey Microsoft device code phishing pages' and Microsoft's Defender Security Research confirmed the campaign as an escalation of the prior Storm-2372 device code phishing campaign from February 2025.
EvilProxy (tracked as O-TA-041 by Okta Threat Intelligence, operating since May 2022) is one of the longest-running commercial AiTM PhaaS platforms. It uses a reverse-proxy architecture that sits between the victim and the legitimate identity provider, proxying the entire authentication flow in real time including MFA challenges. The victim sees a convincing Microsoft-branded page with the target organization's name dynamically populated; the proxy captures both credentials and session cookies in transit. The kit features extensive anti-analysis: VM and browser fingerprinting, IP blocklisting via api.ipify.org, domain blocklisting, and
Weaknesses (CWE)
CWE-287, CWE-306, CWE-523
Target sectors: government administration, finance, health, technology, manufacturing, retail, aviation, insurance, pharmacy, logistics
Target regions: North America, Europe, australia, Middle East, Asia, 005 - South America
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1566, T1098, T1078, T1137, T1027, T1497, T1550, T1557, T1539, T1056