Target Industry
Indiscriminate, opportunistic targeting.
Overview
Threat researchers at the Californian cyber security company SlashNext have discovered a new phishing kit named Astaroth, which poses a significant risk to online account security. The Astaroth phishing kit has several alarming capabilities: it bypasses two-factor authentication (2FA) and circumvents reCAPTCHA and BotGuard.
Additionally, the kit is being sold with custom hosting options, including bulletproof hosting with six months of updates and support for $2,000. While the specific developers of Astaroth have not been publicly identified, it first appeared on cybercrime forums in January 2025. This discovery underscores the evolving threats in cyber security and the need for robust protective measures.
Impact
By bypassing 2FA through session hijacking and real-time credential interception, the Astaroth phishing kit has a substantial impact. It can compromise accounts on platforms like Gmail, Office 365, and Yahoo, as well as other third-party login services. This allows threat actors to gain unauthorised access to sensitive information, potentially leading to identity theft, data breaches, and financial loss.
Exploitation
The Astaroth phishing kit employs a reverse proxy mechanism (a server that directs client requests to the appropriate backend server) to act as a man-in-the-middle between the user and legitimate login pages. This proxy captures all the data entered by the user, including usernames, passwords, and 2FA tokens.
Once the user enters their credentials and 2FA token, Astaroth captures this information in real-time. It then uses the session cookies to hijack the authenticated session, effectively bypassing the 2FA security measure. This allows threat actors to gain unauthorised access to the victim’s account without raising suspicion.
The phishing kit intercepts and forwards the credentials and tokens to the threat actors instantly, enabling them to compromise accounts. This method makes Astaroth particularly dangerous as it can bypass additional security checks and gain access to sensitive information.
Containment, Mitigations & Remediations
Mitigating the risks posed by advanced phishing kits like Astaroth requires a multi-layered approach. Here are some effective strategies:
- Enhancing email security: Using advanced email filtering and implementing more robust multi-factor authentication (MFA) solutions
- Regular software updates: Ensure all systems and software are up to date with the latest security patches, closing any vulnerabilities
- Employee training and awareness: Phishing awareness training and using phishing simulations can help employees recognise and avoid phishing attempts
- Strong password policies: Use of strong, unique passwords along with the use of password managers.
Indicators of Compromise
Some Indicators of Compromise (IoCs) for this type of phishing campaign can be:
- Unusual Login Locations: Login attempts from unexpected geographical locations
- Multiple Failed Login Attempts: Repeated failed sign-ins, indicating attempts to access accounts using stolen credentials
- Unexpected Outbound Network Traffic: Unusual patterns in data leaving the network
- Changes in Account Behaviour: Anomalies in user account activity, such as accessing unusual files or services
- New Software Installations: Unplanned installations or updates, potentially indicating malicious software.
Threat Landscape
The Astaroth phishing kit represents a significant threat due to its advanced capabilities and widespread potential impact. This makes it particularly dangerous as it can compromise accounts that are typically considered secure.
The kit’s availability on cybercrime forums since January 2025 and its relatively affordable price of $2,000 make it accessible to a wide range of cybercriminals. This lowers the barrier to entry for executing sophisticated phishing attacks, potentially leading to a higher volume of attacks and a broader range of targets. Given these factors, the scale of the Astaroth attack could be extensive, affecting numerous individuals and organisations globally.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
Tactics, Techniques, and Procedures (TTPs)
- T1566: Phishing
- T1566:001: Spearphishing Attachment
- T1566:002: Spearphishing Link
- T1078: Valid Accounts
- T1056: Input Capture
- T1557: Adversary-in-the-Middle












