ANY.RUN analysis of 16K+ organizations reveals that 72.7% of finance sector investigations involve phishing, with five major phishing kits (Tycoon2FA, Sneaky2FA, EvilProxy, ClickFix, EvilTokens) accounting for the majority of threats. Attackers increasingly abuse legitimate services and employ session hijacking techniques that bypass traditional MFA. A fake Microsoft authentication page hosted on aditipoddar.org was identified as an example of adversary-in-the-middle phishing infrastructure.
Sneaky2FA
1 post
US Finance Under Phishing Pressure: What the SOC Data Reveals?