Target Industry

Indiscriminate, opportunistic targeting.

Overview

Threat researchers at the Californian cyber security company SlashNext have discovered a new phishing kit named Astaroth, which poses a significant risk to online account security. The Astaroth phishing kit has several alarming capabilities: it bypasses two-factor authentication (2FA) and circumvents reCAPTCHA and BotGuard.

Additionally, the kit is being sold with custom hosting options, including bulletproof hosting with six months of updates and support for $2,000. While the specific developers of Astaroth have not been publicly identified, it first appeared on cybercrime forums in January 2025. This discovery underscores the evolving threats in cyber security and the need for robust protective measures.

Impact

By bypassing 2FA through session hijacking and real-time credential interception, the Astaroth phishing kit has a substantial impact. It can compromise accounts on platforms like Gmail, Office 365, and Yahoo, as well as other third-party login services. This allows threat actors to gain unauthorised access to sensitive information, potentially leading to identity theft, data breaches, and financial loss.

Exploitation

The Astaroth phishing kit employs a reverse proxy mechanism (a server that directs client requests to the appropriate backend server) to act as a man-in-the-middle between the user and legitimate login pages. This proxy captures all the data entered by the user, including usernames, passwords, and 2FA tokens.

Once the user enters their credentials and 2FA token, Astaroth captures this information in real-time. It then uses the session cookies to hijack the authenticated session, effectively bypassing the 2FA security measure. This allows threat actors to gain unauthorised access to the victim’s account without raising suspicion.

The phishing kit intercepts and forwards the credentials and tokens to the threat actors instantly, enabling them to compromise accounts. This method makes Astaroth particularly dangerous as it can bypass additional security checks and gain access to sensitive information.

Containment, Mitigations & Remediations

Mitigating the risks posed by advanced phishing kits like Astaroth requires a multi-layered approach. Here are some effective strategies:

  • Enhancing email security: Using advanced email filtering and implementing more robust multi-factor authentication (MFA) solutions
  • Regular software updates: Ensure all systems and software are up to date with the latest security patches, closing any vulnerabilities
  • Employee training and awareness: Phishing awareness training and using phishing simulations can help employees recognise and avoid phishing attempts
  • Strong password policies: Use of strong, unique passwords along with the use of password managers.

Indicators of Compromise

Some Indicators of Compromise (IoCs) for this type of phishing campaign can be:

  • Unusual Login Locations: Login attempts from unexpected geographical locations
  • Multiple Failed Login Attempts: Repeated failed sign-ins, indicating attempts to access accounts using stolen credentials
  • Unexpected Outbound Network Traffic: Unusual patterns in data leaving the network
  • Changes in Account Behaviour: Anomalies in user account activity, such as accessing unusual files or services
  • New Software Installations: Unplanned installations or updates, potentially indicating malicious software.

Threat Landscape

The Astaroth phishing kit represents a significant threat due to its advanced capabilities and widespread potential impact. This makes it particularly dangerous as it can compromise accounts that are typically considered secure.

The kit’s availability on cybercrime forums since January 2025 and its relatively affordable price of $2,000 make it accessible to a wide range of cybercriminals. This lowers the barrier to entry for executing sophisticated phishing attacks, potentially leading to a higher volume of attacks and a broader range of targets. Given these factors, the scale of the Astaroth attack could be extensive, affecting numerous individuals and organisations globally.

Threat Group

The specific threat group behind this has not been publicly identified at the time of writing.

Tactics, Techniques, and Procedures (TTPs)

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content