A sophisticated phishing tool called “Astaroth” has recently appeared on cybercrime platforms and provides advanced methods for bypassing two-factor authentication (2FA).

It was first advertised in January 2025 and uses session hijacking and real-time credential stealing to compromise Gmail, Yahoo, Office 365, and other accounts.
According to researchers at SlashNext, the Astaroth phishing kit operates via an evilginx-style reverse proxy, intervening between users and legitimate login pages. In this way, it can capture usernames, passwords, 2FA tokens, and session cookies without being detected. Once attackers obtain the session cookies, they can compromise authenticated sessions, bypassing additional security checks.
See also: Phishing attacks abuse CDN and CAPTCHA
Astaroth phishing kit: How does it differ from other tools?
Astaroth’s real-time monitoring capabilities set it apart from traditional phishing kits. Conventional kits capture login credentials but often fail to compromise accounts protected by 2FA. However, Astaroth intrudes between users and legitimate login pages and dynamically forwards tokens, allowing attackers to gain access once authentication is complete.
“Attackers are now using man-in-the-middle reverse proxies to impersonate legitimate sites, capturing usernames, passwords, 2FA tokens, and session cookies on the fly,” explained Jason Soroko, senior partner at Sectigo. “This method compromises authenticated sessions before security can react, rendering 2FA ineffective.”
See also: Phishing attack targets Ukraine's largest bank
The key features of the Astaroth phishing kit, according to SlashNext, are:
- Real-time credential and session cookie logging
- Using SSL-certified phishing domains to mimic secure sites
- Compatibility with SMS-based codes, push notifications, and authentication apps
How the attack works
The attack begins when victims click on a phishing link, which takes them to a malicious server that acts as a reverse proxy. With SSL certificates, victims are unaware of the threat. Once credentials and tokens are entered, the Astaroth phishing kit steals the data and alerts the attackers.
“With real-time credential sniffing and reverse proxies to compromise authenticated sessions, attackers can bypass even the strongest phishing defenses – including multi-factor authentication (MFA),” said Patrick Tiquet, vice president of security at Keeper Security.

The final phase involves using session cookies to replicate the victim's login environment. This bypasses 2FA entirely, as the session is already authenticated.
Protection
Users should be wary of messages they receive from strangers or from supposedly well-known companies. Many times, phishing attacks start with a simple message asking for the user's login details.
See also: Mobile phishing: What is it and how to protect yourself?
Next, they should regularly update their software, including the operating system and applications. These updates often include security that can protect the user from the latest threats.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Using reliable security software, such as an antivirus or security app, can help protect against attacks. These tools can identify and block suspicious websites or messages that are trying to steal user information.
Finally, users should be careful when downloading applications from the internet. Many times, applications that seem innocent may contain hidden code that can steal user information or cause other security threats.
Source: www.infosecurity-magazine.com
