Astaroth Kit Offered for $2,000 on Telegram, Intercepts Authentication in Real Time. A new phishing kit called Astaroth bypasses two-factor authentication through session hijacking and real-time credential interception from services like Gmail, Yahoo, AOL and Microsoft 365. Acting as a man-in-the-middle, it captures login credentials, tokens and session cookies in real time.
First seen on govinfosecurity.com
Jump to article: www.govinfosecurity.com/new-phishing-kit-bypasses-two-factor-protections-a-27525