At a Glance
| Category | Details |
|---|---|
| Threat Actor / Kit | Sneaky 2FA (suspected Phishing-as-a-Service kit) |
| Activity Type | Adversary-in-the-Middle (AiTM) phishing, session hijacking, malware delivery |
| Targets | Healthcare systems, medical schools, academic medical centers |
| Scale | 1,454 unique recipients across 565 distinct domains |
| Law Enforcement Status | Active cybercrime operation; tracked by threat researchers |
| Primary Source | Security Risk Advisors (SRA) |
TL;DR
Security analysts discovered an active AiTM phishing campaign targeting healthcare providers and medical colleges. The attackers hijack Microsoft 365 sessions and use compromised accounts to send thousands of trusted phishing emails. Furthermore, the campaign deploys remote management tools to establish persistent administrative access.
What Happened in the Healthcare Intrusions
Attackers gained access by compromising a university account, which sent document-sharing notifications to a partner health system. The phishing lure directed recipients to a staging page on Google Sites. Once victims clicked the link, the page redirected them to a harvester domain.
The infrastructure captured credentials and authentication cookies in real time. “SRA identified an active adversary-in-the-middle (AiTM) phishing campaign propagating across healthcare and healthcare-education organizations by chaining compromised accounts.” Shortly after the initial compromise, anomalous sign-ins began from unusual network addresses.
Roughly seven hours later, the attackers turned the stolen account into a launchpad for broader attacks. The compromised account sent over 1,000 phishing emails to external educational domains in just 13 minutes. Recipients at subsequent health systems received messages that appeared to come from a trusted colleague. Consequently, this chaining mechanism accelerated the attack velocity across partner networks.

In addition to stealing sessions, the attackers opened a parallel malware track. Certain phishing links delivered ConnectWise ScreenConnect installers. Attackers abuse this legitimate remote-access tool to establish an unauthorized administrative foothold.
Who Is Behind the Campaign
Security Risk Advisors assesses with moderate confidence that the operation utilizes the Sneaky 2FA phishing kit. This kit operates under the Sneaky Log phishing-as-a-service brand. However, researchers emphasize that this evaluation represents a tooling assessment rather than attribution to a single criminal group. Multiple independent operators purchase access to these phishing kits on underground forums.
The toolkit acts as a reverse proxy between the victim and legitimate login portals. “The attacker then replays the stolen session token rather than the password, so the second factor is never re-challenged and a password reset alone does not evict them.”
The operators also apply aggressive cloaking techniques to conceal their infrastructure. The servers identify automated scanners, sandboxes, and security crawlers, serving them benign decoy pages. As a result, public reputation engines scored these malicious domains as clean.
Impact and Scale of the Attacks
Telemetry revealed that the healthcare AiTM phishing campaign reached 1,454 unique recipients across 565 domains. Healthcare provider organizations represented roughly 47% of all targets. Higher education institutions and medical schools accounted for another 13%.
The campaign also touched related sectors, including medical malpractice insurers and regulatory bodies. The attackers maintained persistent harvesters while frequently rotating the Google Sites staging layers. As researchers noted, “The harvester domain therefore has an operational lifespan of at least six days and is reused across multiple unrelated victims.”
How Organizations Can Stay Protected
Defending against this AiTM phishing campaign requires a multi-layered identity strategy. Organizations cannot rely solely on standard multi-factor authentication or simple password resets.
Revoke Session Tokens Immediately
When incident responders detect a compromised account, they must revoke all active session tokens immediately. Changing the user password does not terminate an active attacker session. Responders should also inspect mailbox rules for unauthorized forwarding commands.
Deploy Phishing-Resistant MFA
Organizations should adopt FIDO2 hardware security keys or certificate-based authentication. These phishing-resistant standards bind authentication sessions to genuine website domains. Therefore, reverse proxy kits cannot steal usable credentials.
Implement Strict Application Controls
Security teams must restrict the installation of unapproved remote management tools. Enforcing software allow-listing blocks unauthorized ScreenConnect deployments before attackers establish network persistence.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!