World

Hackers can now break two-factor authentication security measure

To protect against such attacks, cybersecurity experts advise remaining cautious when clicking on links from unfamiliar sources, particularly in emails or messages from unknown senders.

Updated 1 year ago · Published on 21 Feb 2025 9:40AM

Hackers can now break two-factor authentication security measure
Attackers initiate the breach by sending a fraudulent link to their target – February 21, 2025

HACKERS have developed a new phishing tool capable of bypassing two-factor authentication (2FA), a security measure previously regarded as one of the most effective safeguards for online accounts.

This tool, known as Astaroth, targets popular platforms like Google, Microsoft, and Yahoo by exploiting vulnerabilities in 2FA systems, AFP Relaxnews reported today.

The two-factor authentication is designed to enhance security by requiring users to provide not only a password but also an additional code, typically sent via SMS or email.

This added layer was long considered a strong defense against unauthorized access. However, Astaroth, a sophisticated phishing kit named after the Great Duke of Hell, is proving to be a formidable threat to this security measure.

SlashNext, a cybersecurity firm, was the first to detect this tool, which allows hackers to intercept 2FA codes in real time.

The attackers initiate the breach by sending a fraudulent link to their target, leading them to a fake login page that mimics the legitimate interface of a trusted platform.

Once the victim enters their login credentials and 2FA code, the hackers capture and misuse this sensitive information instantly.

What sets Astaroth apart from other phishing tools is its ability to bypass not just the password but the second layer of security — the 2FA code itself. According to SlashNext, the complete phishing kit is available for purchase on the Dark Web for approximately US$2,000 (RM8,855).

To protect against such attacks, cybersecurity experts advise remaining cautious when clicking on links from unfamiliar sources, particularly in emails or messages from unknown senders.

Additionally, using alternative authentication methods such as passkeys, which rely on biometrics (like fingerprints or facial recognition) or device-stored codes, offers an added layer of protection. These more secure methods are supported by major tech companies, including Apple, Google, and Microsoft. –  February 21, 2025

Spotlight

Malaysia

JPJ temporarily suspends VTA and registration for Chery Omoda 5

Malaysia

Eligibility for PTPTN repayment deferment to be verified with LHDN

Malaysia

Budget allocates two rounds of cash aid to millions of Malaysians in 70th Merdeka year

Malaysia

No Malaysians killed or injured in Riyadh airport attack, says Wisma Putra

Malaysia

JAIS probes viral religious ritual footage, says AI manipulation not ruled out

Malaysia

10-tonne truck ploughs into 11 vehicles: Police probe possible brake failure

World

Trump weighs joining Saudi strikes after deadly Houthi attack on Riyadh airport

You may be interested

World

Bangladesh to deploy army at two new posts near Rohingya camps amid rising crime

World

India releases youth protest leaders after detention as voter-list row deepens

World

Trump calls for Zelenskiy’s removal after deadly Russian strike kills 20 in Ukraine

World

Anak Krakatau raised to second-highest alert after 13 eruptions

World

Gaza ceasefire leaves 2.1 million Palestinians squeezed into 35% of territory as attacks continue

World

Man dies after entering tiger enclosure at UK wildlife park

World

Trump lifts sanctions on Russian diesel as US fuel prices soar ahead of midterms

World

Trump attacks Norway after Nobel Peace Prize goes to Navi Pillay