CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise IT Services & Support in Houston, TX
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Managed Service Provider Houston
Shane
Shane November 19th, 2025

Sneaky2FA Phishing Kit Evolves with Browser-in-the-Browser Pop-ups Targeting Houston Businesses

Houston Businesses Face Sophisticated Phishing Attacks Targeting Microsoft 365 Accounts – Browser-In-The-Browser Attacks Display Fake URLs

Cybersecurity Alert
Sneaky2FA Now Fakes the Whole Microsoft Login Window. Browser-in-the-Browser Phishing Just Made MFA Optional for the Attacker.

A phishing kit sold on Telegram now paints a pixel-perfect Microsoft sign-in pop-up inside the page and steals the session token behind it. Houston businesses on Microsoft 365 are the target.

TL;DR
Push Security found the Sneaky2FA phishing-as-a-service kit now runs a browser-in-the-browser (BitB) attack: a fake Microsoft login window, drawn in HTML and CSS, that carries a real reverse-proxy behind it to steal your password and live session token in one shot. Because it captures the session, it walks past MFA. For a Houston SMB on Microsoft 365, the address-bar habit you trained your staff on no longer catches this one.
🪟 What BitB Actually Is 🎣 How the Attack Runs 🛑 Why MFA Does Not Save You 🚀 How CinchOps Helps

Sneaky2FA is a phishing kit rented on Telegram, and it just learned a new trick: it fakes the entire Microsoft login window. Not the page behind it, the window itself, chrome and address bar and all. That is the browser-in-the-browser attack, and it defeats the one thing you taught your team to check.

The kit is not new. The security firm Sekoia found Sneaky2FA in December 2024, an adversary-in-the-middle service sold through a Telegram bot for about $200 a month. What changed in November 2025 is that Push Security documented Sneaky2FA adding browser-in-the-browser (BitB) capability, a technique that draws a convincing fake pop-up window, complete with a legitimate-looking Microsoft URL, on top of a page the attacker controls. CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, and this is the kind of shift we flag early because it changes what "check the URL" is worth.

Why this hits Houston: almost every business here runs on Microsoft 365 - energy firms, CPA practices, law offices, construction shops. Sneaky2FA targets exactly that login. The kit even redraws its fake window to match your operating system and browser, so a Windows Edge user and a macOS Safari user each see the pop-up that looks right to them.

What Is a Browser-in-the-Browser Attack, in Plain Terms?

A fake window, not a fake page - and that difference is the whole point.

A browser-in-the-browser attack draws a fake pop-up login window inside a web page using ordinary HTML and CSS, so the window that looks like a separate Microsoft sign-in prompt is actually a picture painted on the attacker's page. The researcher known as mr.d0x first documented the technique in March 2022.

Here is the sleight of hand. When a real site sends you to sign in with Microsoft, a genuine browser pop-up opens with a real address bar showing login.microsoftonline.com. The BitB attack recreates that pop-up in code. The title bar, the window controls, the padlock, the address bar text - all drawn on the page. Inside that fake frame sits an iframe pointed at the attacker's phishing server. You read a trusted URL, so you type. In 35 years doing this, the reliable advice was always "look at the address bar before you enter a password." This attack takes that advice and turns it into the trap.

  • The window is fake, the URL text is fake. Both are HTML the attacker wrote, so the reassuring microsoftonline.com in the bar proves nothing.
  • It adapts to your setup. Push Security found the kit renders different window styling for Windows Edge versus macOS Safari, so the fake matches what you expect to see.
  • It does not need a software flaw. BitB abuses how single-sign-on pop-ups normally look. There is no patch for "it looks legitimate."
Animation of a browser-in-the-browser attack drawing a fake Microsoft login pop-up window
A browser-in-the-browser attack in motion. Source: Push Security.
Side-by-side of the fake Sneaky2FA pop-up window rendered for Windows Edge and macOS Safari
The fake pop-up window rendered for Windows Edge and for macOS Safari. Source: Push Security.

How Does the Sneaky2FA Attack Actually Run From Click to Takeover?

A staged lure that filters out security tools before the fake window ever appears.

The Sneaky2FA chain starts with a link to a legitimate-looking page, forces a Cloudflare Turnstile bot check to keep scanners out, shows a fake Adobe Acrobat document prompt, then springs the BitB Microsoft login window that harvests credentials and the session token together.

Every step is built to survive automated inspection. The Turnstile check and conditional loading screen out security crawlers and researchers; visitors who fail the profile get redirected to a harmless page like a Wikibooks article, so an analyst who pokes at the link sees nothing. Only a real, targeted victim reaches the fake window. Because a real reverse proxy sits behind that window, everything the victim types relays live to Microsoft, which means the attacker collects the authenticated session, not just a password.

  • Step one, the lure. An email or message links to a domain dressed up as a document-preview or file-share service.
  • Step two, the gate. A Cloudflare Turnstile bot check loads first, blocking automated security tools from ever seeing the payload.
  • Step three, the bait page. A screen styled like Adobe Acrobat asks you to "Sign in with Microsoft" to view the file.
  • Step four, the fake window. Clicking sign-in triggers the BitB pop-up with its fake Microsoft address bar.
  • Step five, the theft. Your password, your MFA response, and your session token flow straight to the attacker for immediate account takeover.
Fake Adobe Acrobat page prompting the user to sign in with Microsoft as part of the Sneaky2FA phishing lure
The "Sign in with Microsoft" prompt used as the phishing lure. Source: Push Security.
Sneaky2FA phishing page redirecting an unwanted visitor to a benign Wikibooks page to evade analysis
Visitors who fail the profile check get sent to a harmless Wikibooks page. Source: Push Security.
SNEAKY2FA + BITB, BY THE NUMBERS 2022 BitB technique first documented (mr.d0x) Dec '24 Sneaky2FA found by Sekoia $200 per month, rented on Telegram ~100 domains found hosting the kit CinchOps · cinchops.com · Sources: Push Security; Sekoia; mr.d0x
Sneaky2FA and the browser-in-the-browser technique at a glance.

Why Does Standard MFA Not Stop This Attack?

The attacker is not guessing your code. They are stealing the door you already unlocked.

Sneaky2FA does not try to bypass the MFA prompt. It relays your real login to Microsoft through a reverse proxy, lets you complete MFA yourself, then steals the resulting session token. With a valid session in hand, the attacker is already inside, and no second factor is asked again.

This is the part that catches people off guard. Text-message codes, authenticator app approvals, even most one-time codes are all defeated the same way: you pass the check, and the attacker inherits the session behind it. Identity-based attacks are already the leading way businesses get breached, and this kit aims straight at that layer. The defenses that actually hold are the ones the attacker cannot relay - hardware security keys and passkeys built on the FIDO2 standard, which are bound to the real domain and simply refuse to authenticate to the fake window. Everything else on your list buys you detection time, not prevention.

  • The session token is the prize. Once stolen, it is a valid pass that skips the login and the second factor entirely.
  • Phishing-resistant beats phishable. FIDO2 security keys and passkeys are domain-bound, so they will not sign in to a look-alike window.
  • Conditional access narrows the blast. Rules tied to device compliance and location can block a stolen session used from an unmanaged machine.
  • Session monitoring catches the aftermath. Impossible-travel and anomalous-session alerts flag the takeover fast when prevention slips.
100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

We spent 20 years teaching people to check the address bar before they type a password. This kit draws a fake address bar with the right URL in it, so the habit now works against them. The only fix that holds is a login the attacker physically cannot relay - a security key or a passkey. Everything else just tells you it already happened.
Shane Stevens, CEO, CinchOps - LinkedIn

Phishing That Beats MFA Needs Defense That Does Not Depend on It

CinchOps deploys phishing-resistant authentication, conditional access, and live session monitoring so a stolen password does not become a stolen business. It is the core of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Helps Houston Businesses Shut Down Sneaky2FA

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, and we build Microsoft 365 defenses around the assumption that a phishing link will eventually get clicked.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. Against a kit that harvests session tokens and adapts its fake window to each victim, the answer is not a single tool - it is layered controls that make a stolen credential useless:

  • Phishing-resistant authentication. We roll out FIDO2 security keys and passkeys that refuse to sign in to a look-alike domain, closing the door BitB relies on.
  • Conditional access policies. Logins get checked against device compliance, location, and risk, so a session stolen to an unmanaged machine gets blocked.
  • Live session and identity monitoring. Impossible-travel and anomalous-session alerts catch a takeover in minutes, not after the wire transfer.
  • Awareness training built for this attack. We teach teams the one tell BitB cannot fake - a "pop-up" you cannot drag outside the browser window is not a real window.

If you run a business in Houston or Katy on Microsoft 365 - a law firm, a CPA practice, or an energy firm - and your MFA is still text codes or app approvals, you are exactly who this kit is built for. Talk to CinchOps and we will move you to a login an attacker cannot relay.

Frequently Asked Questions

What is Sneaky2FA?

Sneaky2FA is an adversary-in-the-middle phishing-as-a-service kit that Sekoia discovered in December 2024, sold through a Telegram bot for about $200 a month. It targets Microsoft 365 accounts, relaying logins through a reverse proxy to steal passwords and session tokens. In November 2025, Push Security documented it adding browser-in-the-browser capability.

What is a browser-in-the-browser (BitB) attack?

A browser-in-the-browser attack draws a fake pop-up login window inside a web page using HTML and CSS, including a real-looking address bar showing a trusted URL. The window is not real, so the URL proves nothing. The researcher mr.d0x first documented the technique in March 2022; commercial kits like Sneaky2FA now weaponize it.

Why does Sneaky2FA bypass multi-factor authentication?

It does not crack MFA - it relays your real login to Microsoft while you complete MFA yourself, then steals the authenticated session token. With a valid session, the attacker is already inside and is not asked for a second factor again. This is why text codes and app approvals do not stop it.

How can a Houston business defend against this attack?

Move to phishing-resistant authentication - FIDO2 security keys or passkeys that are bound to the real domain and refuse to sign in to a fake window. Add conditional access tied to device and location, plus session monitoring for impossible-travel alerts. Awareness training helps, but on its own it cannot beat a login page this convincing.

Is Sneaky2FA a risk if we already use Microsoft 365 with MFA?

Yes. Any organization on Microsoft 365, Entra ID, or Azure services is a direct target, and standard MFA is the exact control this kit is built to defeat. Houston energy, healthcare, financial, and legal firms are high-value because a compromised account opens email, SharePoint, and OneDrive at once.

Discover More

CinchOps Cybersecurity Services
ClickFix: The Attack That Tricks You Into Infecting Yourself
What Is MDR? Managed Detection and Response Explained
Fake Microsoft OneNote Login Pages: How to Spot Them
Huntress 2025 Threat Report: Log In, Not Break In
CinchOps Managed IT Services

Sources

  • Push Security, Analyzing the latest Sneaky2FA BITB phishing page
  • Sekoia, Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
  • mr.d0x, Browser In The Browser (BITB) Attack (March 2022)
  • The Hacker News, New 'Sneaky 2FA' Phishing Kit Targets Microsoft 365 Accounts
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

March 20th, 2026
Cyber Exploit
CISA Warns Houston Businesses: Critical SharePoint Flaw Under Active Attack

January’s SharePoint Patch Just Became March’s Emergency – Your SharePoint Server Has a Bullseye on It Right Now

September 9th, 2025
Managed Service Provider Houston Cybersecurity
Mid-Year 2025 Cyber Threats: What Houston Businesses Need to Know – CinchOps Analysis

Supply Chain Security Challenges Emerge In Current Threat Analysis – Critical Infrastructure Under Siege From State-Sponsored Groups

March 12th, 2026
IT Guide
Why Every Growing Houston Business Needs an IT Guide to Cut Through the Clutter

How A Managed IT Partner Brings Order To Growing Businesses – Growth Exposed Your IT Shortcuts, Here’s How To Fix Them

June 15th, 2026
Cybersecurity Housotn
Your Update Button Is Lying to You About Houston Cybersecurity

Patch Management vs Automatic Updates: What Houston Businesses Need to Know – Why MSP Patch Management Beats Turning On Automatic Updates

October 24th, 2025
Managed Service Provider Houston Cybersecurity
Ransomware Attacks on Critical Infrastructure Surge 34% in 2025: Is Your Houston Business at Risk?

How Ransomware-As-A-Service Platforms Fuel The 4,701 Cyberattacks Recorded In 2025 – Layered Defense Strategy Essential As Traditional Perimeter Security Proves Inadequate

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery for Houston Businesses
  • Cloud Services
  • Business Process Automation for Houston Businesses
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy