MITE RADIO 0492 906 469
  • MITE RADIO
  • Volunteer
  • Thank You
  • Blog
  • Programs
    • Making IT Easy with Tony & Kay
    • The Blues Hotel ​with Kelvin Huggins
    • Jazz Fusion with Brett C
    • Pheez Feels
    • Able & Unfiltered
    • Glenn & Tracy's Timeless Tracks
    • Cort In The Morning
    • Hits, Quizzes & Stuff with Harley Buckner
    • Solid Gold Sounds - Chris Pitchford
    • Gordon Cooper (multiple programs)
    • The Vinyl Countdown with Jonathan Charles
    • 50 Years and Rolling with Leo Kirby
    • Soul Vaults with David Southway
    • The Best Disco In Town with Jonathan Charles
    • ABC Oldies - JP McCartney
    • 50 Years of Pop with Peter Kirkpatrick
    • All About The 80s with Rob Charles
    • No More Heroes with Magnus Shaw
    • Classic Chart Rundowns with Dave Marley (multiple programs)
    • US UK Rock Soul Connection
    • Decades Breakfast with Mark Gale
    • Flashback to the 60s with Jim Barrington
    • The Time of Our Musical Life with Geoff Wood
    • Steve Bishops Old Record Club
    • Steve Algar ​(multiple programs)
    • Chris Palin ​(multiple programs)
    • The Peter Nightingale Show
    • Deeper Dimensions with David Dyke
    • Choice Cuts with Kevin Butcher
    • Ken Anton (Multiple Programs)
    • Gary Hopkins (Multiple Programs)
  • WAYS TO LISTEN
Picture
​

click here to listen
​to Mite radio (then click the red play arrow)
An initiative of ​The Stairway Project Inc
Picture

2FA Hijacking

28/2/2025

0 Comments

 
A new phishing kit called Astaroth is exploiting a vulnerability in two-factor authentication (2FA), putting millions of Gmail and Outlook users at risk.

The kit, which was first advertised last month, allows hackers to steal 2FA codes and session cookies in real-time, effectively bypassing this critical security measure. This is achieved through a "man-in-the-middle" attack, where the user is redirected to a fake login page that mimics the appearance of the legitimate site.
​
Picture
This type of attack bypasses two-factor authentication through session hijacking and real-time credential interception.

Traditional phishing attacks typically capture only primary credentials, leaving 2FA intact. However, Astaroth intercepts all authentication data in real-time, rendering 2FA ineffective.

How the Attack Works:

  1. Users click on a malicious link, often disguised within a seemingly legitimate email or message.
  2. They are redirected to a fake login page that mirrors the appearance of Gmail, Outlook, or another email platform and you are prompted to login.
  3. When users enter their login credentials and 2FA code, this information is instantly captured by the attackers.
  4. The attackers can then access the user's account, even though they have the correct 2FA code.

What You Can Do:

  • Never click on links in emails or messages, even if they appear to be from a trusted source.
  • Always navigate to login pages directly through your browser or app.
  • Be wary of any suspicious pop-up windows or requests for personal information.
  • Consider using passkeys, a more secure authentication method that is not vulnerable to this type of attack.

This phishing kit is readily available for purchase on cybercrime marketplaces for $2,000, making it a serious threat to users. It is crucial to remain vigilant and follow best practices to avoid falling victim to this attack.

Ep305
Image created by AI
More on miteradio.com.au (press play)
0 Comments

Your comment will be posted after it is approved.


Leave a Reply.

    Author

    Delve into the world of MITE Radio through our captivating blogs. From music and tech to community news, our articles offer fresh perspectives and behind-the-scenes glimpses. Stay informed, connect with our community, and explore MITE Radio in a new way today!

    Archives

    June 2025
    May 2025
    April 2025
    March 2025
    February 2025
    January 2025
    December 2024
    November 2024
    October 2024
    September 2024
    August 2024
    July 2024
    June 2024
    May 2024
    April 2024
    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    June 2023
    May 2023
    April 2023

    Categories

    All
    AI
    App Of The Day
    Bytes & Beats
    Cyber Security
    Discussion
    Gadgets & Gizmos
    Game
    Innovation Hub
    Listener Question
    News
    Other
    Somethin' For Nothin'
    The Tech Absurd
    Tips & Tricks

    RSS Feed



  • MITE RADIO
  • Volunteer
  • Thank You
  • Blog
  • Programs
    • Making IT Easy with Tony & Kay
    • The Blues Hotel ​with Kelvin Huggins
    • Jazz Fusion with Brett C
    • Pheez Feels
    • Able & Unfiltered
    • Glenn & Tracy's Timeless Tracks
    • Cort In The Morning
    • Hits, Quizzes & Stuff with Harley Buckner
    • Solid Gold Sounds - Chris Pitchford
    • Gordon Cooper (multiple programs)
    • The Vinyl Countdown with Jonathan Charles
    • 50 Years and Rolling with Leo Kirby
    • Soul Vaults with David Southway
    • The Best Disco In Town with Jonathan Charles
    • ABC Oldies - JP McCartney
    • 50 Years of Pop with Peter Kirkpatrick
    • All About The 80s with Rob Charles
    • No More Heroes with Magnus Shaw
    • Classic Chart Rundowns with Dave Marley (multiple programs)
    • US UK Rock Soul Connection
    • Decades Breakfast with Mark Gale
    • Flashback to the 60s with Jim Barrington
    • The Time of Our Musical Life with Geoff Wood
    • Steve Bishops Old Record Club
    • Steve Algar ​(multiple programs)
    • Chris Palin ​(multiple programs)
    • The Peter Nightingale Show
    • Deeper Dimensions with David Dyke
    • Choice Cuts with Kevin Butcher
    • Ken Anton (Multiple Programs)
    • Gary Hopkins (Multiple Programs)
  • WAYS TO LISTEN