Phishing-as-a-Service Rockstar 2FA continues to be prevalent

Share:

Trustwave researchers are monitoring malicious activity associated with Phishing-as-a-Service (PaaS) platforms, their latest report focuses on a toolkit called Rockstar 2FA.

Rockstar 2FA targets Microsoft 365 accounts and bypasses multi-factor authentication with adversary-in-the-middle (AitM) attacks.

In AiTM phishing, threat actors set up a proxy server between a target user and the website the user wishes to visit, which is the phishing site under the control of the attackers. The proxy server allows attackers to access the traffic and capture the target’s password and the session cookie.

The experts observed a phishing campaign targeting Microsoft 365 users with adversary-in-the-middle attacks that has surged since August 2024. A unique feature of the campaign is the use of car-themed web pages, with over 5,000 related domains identified since May 2024.

The Rockstar 2FA PhaaS is an updated version of the DadSec/Phoenix phishing kit.

“The revamped phishing kit is still operating under the PaaS model, with marketing and communications observed on ICQ, Telegram, and Mail.ru. With these platforms, the kit becomes easily accessible for other cybercriminals seeking to acquire easy-to-set up phishing tools.” reads the report published by Trustwave.

The subscription fee for the PhaaS is $200 for two weeks, $350 for a month, US$180 for a two-week API renewal service.

Authors advertise Rockstar 2FA as a phishing-as-a-service toolkit that bypasses 2FA, harvests cookies, and features FUD links, antibot tools, and custom themes.

The Rockstar admin panel is user-friendly, it allows customers to track phishing activity, including visit stats and account validity, and offers tools like URL generators and customizable email themes.

Rockstar 2FA phishing campaigns use diverse themes, including file-sharing, HR notices, MFA lures, and account alerts. The toolkit evades detection with FUD links, obfuscation, and QR codes.

The Rockstar 2FA kit bypasses antispam detection with legitimate link redirectors and uses Cloudflare Turnstile antibot checks to prevent automated page analysis.

Trustwave observed threat actors using trusted services like Atlassian Confluence, Google Docs Viewer, and Microsoft OneDrive to host phishing links.

“Commodity phishing attacks, such as campaigns linked to the Rockstar 2FA PaaS platform, continue to be prevalent due to their low cost and ease of deployment. With the integration of AiTM techniques, additional layers of security like MFA can be bypassed. The likelihood of secondary attacks, such as account takeovers, launching phishing campaigns using compromised accounts, or performing business email compromise (BEC) attacks, also increases.” concludes the report.

“Given the continued Rockstar-led phishing activities, it is more likely that the threat actors behind this PaaS will continue updating this kit or develop even more advanced phishing kits.”

Pierluigi Paganini

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:59 pm, Jun 27, 2025
weather icon 19°C
L: 18° | H: 20°
few clouds
Humidity: 79 %
Pressure: 1022 mb
Wind: 10 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 20%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:45 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
18° | 20°°C 0 mm 0% 11 mph 82 % 1025 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 7 mph 77 % 1026 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
21° | 35°°C 0 mm 0% 9 mph 65 % 1021 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
21° | 33°°C 0 mm 0% 10 mph 71 % 1016 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
17° | 25°°C 1 mm 100% 13 mph 82 % 1017 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 10 mph 79 % 1022 mb 0 mm/h
Tomorrow 4:00 am
weather icon
19° | 19°°C 0 mm 0% 9 mph 82 % 1022 mb 0 mm/h
Tomorrow 7:00 am
weather icon
20° | 20°°C 0 mm 0% 8 mph 82 % 1023 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 9 mph 74 % 1024 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
27° | 27°°C 0 mm 0% 11 mph 54 % 1024 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 11 mph 50 % 1023 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
27° | 27°°C 0 mm 0% 10 mph 51 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 68 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,481.20
0.13%
Ethereum(ETH)
€2,069.55
0.38%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.83
1.54%
Solana(SOL)
€121.91
2.53%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.137820
1.18%
Shiba Inu(SHIB)
€0.000009
1.03%
Pepe(PEPE)
€0.000008
0.00%
Scroll to Top