Threats Tagged '2fa bypass'
View all threats tagged with '2fa bypass'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged '2fa bypass'
Click on any threat for detailed analysis and mitigation recommendations
Mirage2FA is a phishing-as-a-service toolkit that hijacks Microsoft 365 sessions by stealing credentials and authenticated sessions via Adversary-in-the-Middle attacks. It targets corporate users primarily in the US, affecting industries such as Technology, Manufacturing, and Education. The toolkit uses browser-based delivery methods including HTML smuggling, QR codes, JavaScript obfuscation, and WebSocket communication to bypass two-factor authentication. Between 2024 and 2026, it compromised over 4,500 Microsoft 365 accounts out of approximately 9,400 targeted email addresses, enabling attackers to access corporate email, sensitive data, and trusted business accounts. MediumCampaign Join the discussion | AlienVault OTX General | 08/18/2026, 20:48:20 UTC Added: 08/19/2026, 10:04:41 UTC |
The UNC1151/Ghostwriter group is conducting high-intensity phishing campaigns targeting Gmail accounts of Polish citizens since March 2026. The campaigns primarily target individuals in political and public life, prominent positions, researchers, journalists, public administration and law enforcement employees, and their associates. Attackers use fraudulent emails impersonating Gmail administrators, claiming suspicious activity or policy violations to pressure victims into verifying their accounts. The phishing infrastructure captures login credentials and two-factor authentication codes through fake login panels. The group utilizes dedicated domains, Netlify subdomains, and compromised websites to host phishing pages. Campaigns run primarily on weekdays with new domains appearing almost daily, demonstrating persistent operational tempo against Polish targets. Join the discussion | AlienVault OTX General | 06/12/2026, 16:57:58 UTC Added: 06/15/2026, 18:45:13 UTC |
A new Phishing-as-a-Service (PhaaS) framework dubbed Salty 2FA has been discovered targeting industries in the US and EU. It uses a unique domain pattern combining .com subdomains with .ru domains and employs a multi-stage execution chain to resist detection. The kit can bypass multiple 2FA methods, including push, SMS, and voice. Victims span global industries such as finance, telecom, energy, consulting, logistics, and education. Static IOCs are unreliable for detection; instead, behavioral patterns must be identified. The framework shares traits with Storm-1575 but has distinct characteristics setting it apart from known threats like Tycoon2FA or EvilProxy. It demonstrates sophisticated capabilities in distributing phishing payloads, maintaining dynamic infrastructure, and managing complex communication between phishing pages and C2 servers. Join the discussion | AlienVault OTX General | 08/19/2025, 17:08:35 UTC Added: 08/19/2025, 21:32:47 UTC |
Showing 1 to 3 of 3 results