Security Warning Gmail, Outlook, Yahoo & AOL Accounts as Hackers Can Now Bypass 2FA

Security Warning Gmail, Outlook, Yahoo & AOL Accounts as Hackers Can Now Bypass 2FA

If you have a Google Gmail, Microsoft Outlook, Yahoo or AOL account and think you are protected against hackers because you have enabled two-factor authentication (2FA), think again!

Hackers now have a new attack method that bypassed two-factor authentication through session hijacking and real-time credential interception.

Below is an example of the fake sign-in page which you need to avoid.

Next Century Security Warning for Gmail Outlook Yahoo AOL Accounts as Hackers Now Can Bypass 2FA
Typical Attack Popup as reported by Slashnext

The warning comes courtesy of SlashNext, which has just published a report into a new phishing kit dubbed Astaroth.

On infected devices, this deploys a man-in-the-middle attack between user and legitimate account sign-in page, “capturing login credentials, tokens, and session cookies in real time, effectively bypassing 2FA.”

SlashNext warns that “in contrast, traditional phishing kits typically rely on static fake login pages that capture only primary credentials, often leaving the 2FA layer intact. By dynamically intercepting all authentication data in real time, Astaroth significantly raises the bar, rendering conventional phishing methods and their inherent security measures largely ineffective.”

How Astaroth 2FA Attack Works

Like most scams, they all begin with the end user clicking on a link which you can avoid following the basic security guidelines of not clicking on links in emails, text messages or social media posts unless you are 100% sure it is legit.

Once a user clicks on the link, it will redirect them to a malicious server “which mirrors the target domain’s appearance and functionality while relaying traffic between the victim and the legitimate login page.”

So, if you selected Google as your provider, that’s the sign-in page you will be then taken to and there are no visible security warnings, you will assume you are on a legitimate website.

This man in the middle (MITM) attack intercepts your data and feeds the real webpage behind the scenes, with attacker then replicates the victim’s session.

“Because 2FA is always involved (e.g., via SMS codes, authenticator apps, or push notifications), Astaroth automatically captures the entry of the 2FA token in real time. It also ensures that any token entered by the victim is intercepted immediately, the attacker is instantly alerted through a web panel interface and Telegram notifications.”

Two-factor authentication (2FA) is completely undermined by this attack which is why passkeys are now starting to become more popular.

The Astaroth phishing kit in inexpensive and now available to scammers on the black web, “For $2,000, users receive six months of continuous updates, gaining access to the latest improvements and bypass techniques. To build trust, Astaroth offers testing before purchase, showcasing its legitimacy on cybercrime marketplaces.”

Remember, while many phishing lures remain quite basic and obvious, AI is changing this and they will become harder to detect.

Simple Steps to Avoid Scams

  • Do not click links.
  • Do not use sign-in popups for the platforms you use except through usual login methods.
  • If you need to validate your account, navigate to a sign-in page through usual channels, never through a link unless it’s one you’ve just requested from a usual channel.
  • Be careful when using Search Engines to find links to financial sites or security logins 

 

Related Posts
Leave a Reply

Your email address will not be published.Required fields are marked *