Security researchers are warning of attacks that leverage a phishing-as-a-service (PhaaS) toolkit, dubbed Rockstar 2FA, to steal credentials for Microsoft 365 accounts.

“This malicious campaign includes an AitM [adversary-in-the-middle] attack, which allows attackers to intercept user credentials and session cookies. This means that even users with multi-factor authentication (MFA) enabled are still vulnerable,” said Trustwave researchers Diana Solomon and John Kevin Adriano.
Researchers believe the Rockstar 2FA toolkit is an updated version of the DadSec (also known as Phoenix) phishing kit. Microsoft is tracking the developers and distributors of the Dadsec PhaaS platform as Storm-1575.
See also: “GoIssue” phishing tool targets GitHub users
Like its predecessors, Rockstar 2FA is being advertised through services like ICQ, Telegram, and Mail.ru. Interested parties can pay a $200 subscription for two weeks (or $350 for a month). Cybercriminals with little to no technical expertise can leverage it to carry out effective phishing attacks.
The developers say that Rockstar 2FA includes authentication (2FA) bypass capability two-factor , 2FA cookie collection, antibot protection, login page themes that mimic popular services, untraceable links (FUD), and Telegram bot integration.
The phishing kit is also said to feature a “modern, user-friendly dashboard” that allows customers to monitor the status of their phishing attacks, generate URLs and attachments, and even customize themes applied to the links generated.
According to Trustwave, phishing attacks include URLs, QR codes, and attachments, which are embedded in messages sent from compromised accounts or spamming tools. The emails use various templates as bait, ranging from file sharing notifications to requests for electronic signatures.
See also: Xiū gǒu: New phishing kit targets users in 5 countries
Attackers legitimately use link redirectors (e.g., URL shorteners, open redirects, URL protection services, or URL rewrite services) to bypass spam detection, but the Rockstar 2FA phishing kit also incorporates antibot checks using Cloudflare Turnstile in an attempt to prevent automated analysis of AitM phishing pages.
Trustwave said it observed that the platform uses legitimate services such as Atlassian Confluence, Google Docs Viewer, LiveAgent, Microsoft OneDrive, OneNote, and Dynamics 365 Customer Voice to host phishing links. This is because users trust these platforms and are therefore more likely to fall for the trap.
“The phishing pages closely resemble login pages of well-known services despite the numerous obfuscations applied to the HTML code,” the researchers said. “All data provided by the user on the phishing page is immediately sent to the AiTM server. The extracted credentials are used to retrieve the session cookie of the target account.”

Protection
Users should be wary of messages they receive from strangers or from supposedly well-known companies. Many times, phishing attacks start with a simple message asking for the user's login details.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Phishing: Using SVG files to avoid detection
Next, they should regularly update their software, including the operating system and applications. These updates often include security that can protect the user from the latest threats.
Using reliable security software, such as an antivirus or security app, can help protect against attacks. These tools can identify and block suspicious websites or messages that are trying to steal user information.
Finally, users should be careful when downloading applications from the internet. Many times, applications that seem innocent may contain hidden code that can steal user information or cause other security threats.
Source: thehackernews.com
