Skip to content
Skip to content
June 25, 2026
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy

Microsoft News Now

The Home of Microsoft News Today

Primary Menu
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Light/Dark Button
Subscribe

Home - News - Security alert: Sophisticated Rockstar 2FA phishing campaign actively targeting vulnerable Microsoft 365 Users

  • News

Security alert: Sophisticated Rockstar 2FA phishing campaign actively targeting vulnerable Microsoft 365 Users

Dave W. Shanahan 2 years ago (Last updated: 1 year ago) 2 minutes read
Microsoft 365 Hits 430 Million Paid Seats as Copilot and Power Platform Drive AI Adoption

A sophisticated new phishing-as-a-service (PhaaS) platform named Rockstar 2FA has emerged as a significant threat to Microsoft 365 users, marking a concerning evolution in cybersecurity threats. As reported by BleepingComputer, this advanced phishing toolkit, which has been operational since May 2024, has already established over 5,000 phishing domains and continues to pose an active threat to organizations worldwide.

How Rockstar 2FA works

Rockstar 2FA
Rockstar 2FA’s attack flow
(Image: Trustwave)

The platform employs advanced Adversary-in-the-Middle (AiTM) techniques to bypass traditional security measures, including multi-factor authentication (MFA)[3]. The attack process begins when users are directed to a convincing replica of the Microsoft 365 login page. When victims enter their credentials, the platform’s proxy server forwards these details to Microsoft’s legitimate service while simultaneously capturing the session cookie.

Sophisticated distribution methods

What makes Rockstar 2FA particularly dangerous is its distribution through compromised email marketing platforms, lending legitimacy to its phishing attempts. The campaign utilizes various deceptive messages, including:

  1. Document sharing notifications
  2. IT department alerts
  3. Password reset requests
  4. Payroll-related communications

Technical capabilities

The platform, available to cybercriminals for $200 for a two-week subscription, includes several advanced features:

  1. Automated FUD (Fully Undetectable) attachments and links
  2. Cloudflare Turnstile Captcha integration
  3. Multiple login page themes with automatic organization branding
  4. Real-time logging and backup options

Evolution from previous threats

Trustwave security researchers have identified Rockstar 2FA as an updated version of the DadSec and Phoenix phishing kits, which gained notoriety in 2023. Microsoft tracks the developers under the designation Storm-1575, indicating its significance as an emerging threat cluster.

Impact and reach

Since its emergence in May 2024, the platform has seen significant growth, with peak activity recorded in August 2024. The campaign has demonstrated remarkable success in bypassing traditional security measures, making it a particularly concerning threat for organizations relying on Microsoft 365 services.

Security implications

The emergence of Rockstar 2FA represents a significant escalation in phishing capabilities, as it effectively neutralizes one of the most widely recommended security practices – multi-factor authentication. The platform’s success rate and sophisticated approach indicate a new chapter in cybersecurity threats, requiring organizations to reassess their security protocols.

Prevention measures

Organizations using Microsoft 365 should implement additional security layers beyond traditional MFA, including:

  1. Advanced email filtering systems
  2. Regular security awareness training
  3. Monitoring for suspicious login attempts
  4. Implementation of zero-trust security frameworks

The rise of Rockstar 2FA demonstrates the evolving sophistication of cyber threats targeting Microsoft 365 users. As this threat continues to develop, organizations must remain vigilant and adapt their security measures accordingly.

About The Author

Rockstar 2FA

Dave W. Shanahan

I’m Dave W. Shanahan, a Microsoft enthusiast with a passion for Windows, Xbox, Microsoft 365 Copilot, Azure, and more. I started MSFTNewsNow.com to keep the world updated on Microsoft news. Based in Massachusetts, you can email me at davewshanahan@gmail.com.

See author's posts

Like this:

LikeLoading…

Related


Discover more from Microsoft News Now

Subscribe to get the latest posts sent to your email.

Tags: AuthenticationCybersecurityDeveloperMicrosoftMicrosoft 365Security

Post navigation

Previous: Microsoft is pulling the plug Xbox Avatar Editor app, signaling the death of digital self-expression in January 2025
Next: Microsoft faces £1 billion UK antitrust lawsuit over Azure cloud computing practices

Related Stories

XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs
  • News

Unfortunately Expected: XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs

Dave W. Shanahan 31 minutes ago 0
XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend
  • News

XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend

Dave W. Shanahan 1 hour ago 0
Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI
  • News
  • AI and Copilot

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI

Dave W. Shanahan 2 days ago 0

AccessibilityAmazonAndroidAuthenticationAzureCall of DutyCopilotCybersecurityDeveloperEnterpriseFree Play DaysGamingGenerative AIGitHubGoogleLinkedinMicrosoftMicrosoft 365Microsoft 365 CopilotMicrosoft CopilotMicrosoft EdgeMicrosoft StoreMicrosoft TeamsNext Week on XBOXOpenAIOutlookPatch TuesdayPrivacySecuritySettingsSharePointSurfaceTwitterWindowsWindows 10Windows 11Windows InsiderXBOXXBOX Game PassXBOX Game Pass UltimateXBOX OneXBOX Play AnywhereXBOX Series XXBOX Series X|SXBOX Wire

Useful Links

  • AI and Copilot (249)
  • Azure & Cloud (35)
  • Developers (3)
  • Enterprise (3)
  • How To Guides (98)
  • Microsoft 365/Office (95)
  • Microsoft Announcements (97)
  • News (1,264)
  • Security (78)
  • Surface (47)
  • Windows (166)
  • XBOX and Gaming (411)

You May Have Missed

XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs
  • News

Unfortunately Expected: XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs

Dave W. Shanahan 31 minutes ago 0
XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend
  • News

XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend

Dave W. Shanahan 1 hour ago 0
Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI
  • News
  • AI and Copilot

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI

Dave W. Shanahan 2 days ago 0
Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence
  • News
  • XBOX and Gaming

Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence

Dave W. Shanahan 2 days ago 0
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Copyright © 2026 All rights reserved. ReviewNews by AF themes.

    %d