Connect with us

Technology

New phishing attack uses real-time interception to bypass 2FA

Published

on

New phishing attack uses real-time interception to bypass 2FA

Phishing attacks are everywhere, and most of us can spot the obvious ones. Even if someone falls for one and hands over their password, two-factor authentication (2FA) usually adds a crucial layer of protection. But a new phishing kit making the rounds can bypass 2FA entirely by using session hijacking and real-time credential interception.

Known as Astaroth, this tool intercepts and manipulates traffic between your device and legitimate authentication services like Gmail, Yahoo and Microsoft. Since it grabs everything in real time, it completely bypasses 2FA and gives attackers full access to your account.

Stay protected & informed! Get security alerts & expert tech tips – sign up for Kurt’s The CyberGuy Report now.

Illustration of a hacker at work (Kurt “CyberGuy” Knutsson)

How Astaroth works

Astaroth is a next-level phishing kit that takes scamming to a whole new level. Instead of using basic fake login pages like traditional phishing kits, it works as a middleman between your device and the real authentication service while silently grabbing everything needed to break in.

Advertisement

The attack begins when you click on a phishing link and land on a malicious site that looks identical to the real one. Since the site has valid SSL certificates, there are no red flags, no security warnings and no sketchy pop-ups. When you enter your login details, including username, password, device info and IP address, Astaroth snatches them up before passing the request to the actual website.

Two-factor authentication is not a problem for Astaroth. It intercepts one-time passwords the second they are entered, whether they come from an authenticator app, SMS or a push notification. The stolen codes are instantly sent to the attacker through a web panel or Telegram alert, so they can use them before they expire.

The real kicker is that Astaroth also grabs session cookies, which are the small bits of data that keep users logged in after authentication. Attackers can inject these cookies into their own browsers, skipping the need for passwords or two-factor authentication altogether. Once they have the session, they are in with no extra steps required.

An example of what the victim and attacker would see (SlashNext) (Kurt “CyberGuy” Knutsson)

BEST ANTIVIRUS FOR MAC, PC, IPHONES AND ANDROIDS – CYBERGUY PICKS

Advertisement

Astaroth is shockingly advanced

As reported by cybersecurity company SlashNext, Astaroth stands out from other phishing kits because of its ability to intercept credentials in real time, automate attacks and resist takedown efforts. Traditional phishing depends on tricking victims into entering their credentials on fake login pages, but Astaroth removes that step entirely. 

Beyond its advanced capabilities, Astaroth comes with features that make it appealing to cybercriminals. It uses bulletproof hosting to stay online despite law enforcement efforts, receives frequent updates to bypass security patches and follows a structured payment model. For $2,000, buyers get six months of continuous upgrades. To build trust, the creators even let hackers test the phishing kit before purchasing.

Astaroth is widely available through Telegram and underground cybercrime forums. The anonymity of these platforms makes it difficult for authorities to track distribution.

The seller sharing information on testing the phishing kit out (SlashNext) (Kurt “CyberGuy” Knutsson)

HOW TO PROTECT YOUR DATA FROM IRS SCAMMERS THIS TAX SEASON

Advertisement

Signs you may be infected with Astaroth

1) Unexpected account logins or security alerts

  • You receive alerts from Gmail, Microsoft or other services about a login from an unknown device or location
  • You get a 2FA request when you weren’t trying to log in

2) You’re mysteriously logged out of accounts

  • If your session cookies were stolen, an attacker might log in as you and force a log-out elsewhere

3) Password changes or settings updates you didn’t make

  • If an attacker has control, they may change recovery emails, phone numbers or passwords

4) Slow system performance or odd behavior

  • Astaroth uses legitimate Windows processes (like WMIC, BITSAdmin or Regsvr32) to hide itself
  • If your system is sluggish or the Task Manager shows strange processes using high CPU/network with no explanation, that could be a clue

5) Browser acting strangely

  • Login fields autopopulate incorrectly or redirect loops occur
  • Pages that used to work suddenly trigger warnings or errors

6) Unfamiliar programs or scripts running in the background

  • Check for odd Scheduled Tasks, Registry changes or background network connections (especially if they’re outbound to suspicious domains or IPs).

What to do if you suspect infection

  1. Disconnect from the internet immediately
  2. Run a full malware scan using trusted antivirus software
  3. Check for unauthorized logins on your major accounts and change all passwords on another trusted device
  4. Enable passkeys or hardware security keys where possible
  5. Reset your device if malware persists; a full factory reset may be required
  6. Monitor bank accounts and email inboxes for suspicious activity

4 ways to stay safe from Astaroth phishing attacks

1) Avoid unknown links and use strong antivirus software: Remember that no matter how advanced the malware is, it still needs input from you. In most cases, an attacker will require you to click a link before they can steal your data. For example, for Astaroth to work, you have to click a link, visit a malicious website and enter your credentials. If you don’t click the link, you stay clear of the malware.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS device.

2) Double-check sites: Always verify website addresses and use bookmarks for trusted sites. Instead of clicking on links in emails or messages, manually type the URL or use a trusted bookmark. This minimizes the risk of landing on a fraudulent page designed to mimic a legitimate website.

3) Update your devices: You might wonder how keeping your devices updated helps against malware like Astaroth. While it doesn’t directly prevent an attack, it ensures the situation doesn’t get worse. Keeping your operating system and applications up to date with the latest security patches closes vulnerabilities that malware might exploit, making it harder for attackers to gain a foothold on your device.

4) Avoid typing passwords: Avoid entering passwords whenever possible to reduce the risk of credential theft. Instead, use authentication methods like passkeys, Google Sign-In or Apple Sign-In.

Advertisement

A passkey is a feature that uses cryptographic key pairs to verify your identity, eliminating the need for traditional passwords. It allows you to sign in to apps and websites using the same process you use to unlock your device, such as biometrics, PIN or pattern.

Google Sign-In is a feature that allows you to log in to third-party apps or websites using their Google Account credentials. It simplifies the sign-in process by eliminating the need to create and remember separate usernames and passwords for each service. You can sign in via a “Sign in with Google” button, a Google sign-in prompt or automatic sign-in if previously authorized.

Apple Sign-In is a feature that enables you to privately sign in to participating third-party apps and websites using your Apple ID. It offers a fast, easy and more private way to authenticate without the need to create new accounts or remember additional passwords. To set up an account to “Sign in with Apple,” when a participating website or app asks you to set up or upgrade an account, do the following: Tap Sign in with Apple. Follow the onscreen instructions. Some apps (and websites) don’t request your name and email address. In this case, you simply authenticate with Face ID or Touch ID (depending on your model), then start using the app. Others may ask for your name and email address to set up a personalized account. When an app asks for this information, Sign in with Apple displays your name and the personal email address from your Apple Account for you to review.

These methods rely on cryptographic keys or secure tokens, making it much harder for attackers to intercept your login information, even if they manage to trick you into visiting a malicious site.

FBI WARNS OF DANGEROUS NEW ‘SMISHING’ SCAM TARGETING YOUR PHONE

Advertisement

Kurt’s key takeaway

Astaroth shows just how far phishing kits have come, taking things beyond the usual tricks and bypassing 2FA with ease. It’s a reminder that no matter how secure we think our systems are, there’s always a smarter attack waiting to exploit the gaps. Cybercriminals are adapting fast, and while traditional defenses may not cut it anymore, there are still steps you can take to fight back: use passwordless logins, stay updated and keep learning about these evolving threats. 

What do you think governments and companies should be doing to protect you from sophisticated cyber threats like the Astaroth phishing kit, which can bypass traditional security measures? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Advertisement

Answers to the most-asked CyberGuy questions:

New from Kurt:

Copyright 2025 CyberGuy.com. All rights reserved.

Technology

Soundcore new Space 2 promise improved ANC and sound

Published

on

Soundcore new Space 2 promise improved ANC and sound

We finally have an update to the Soundcore Space One that launched two and a half years ago. At MWC 2026, Soundcore has announced the Space 2, which will be available in the US on April 21st in three colors — linen white, jet black, and seafoam green — for $129.99. That’s $30 more than the Space One’s original price.

According to Soundcore, the Space 2 have had a full-band noise cancellation upgrade with the focus of those improvements on the low-frequency sounds we all generally use ANC headphones to block — things like airplane, train, and bus engine sounds while traveling. The Space 2 use the same number of microphones as the Space One for noise canceling, instead relying on optimized mic placement and structure and materials improvements for the boost in performance.

Redesigned 40mm drivers incorporate dual layers in their design. There’s a silk diaphragm with metal ceramic that supposedly results in faster transient response — the driver’s ability to respond to sudden sound quickly and accurately — with better balanced sound reproduction. The Space One had great sound performance for the price, but I’m all for any improvement to sound performance accuracy. Like the Space One, the Space 2 will support LDAC high-res audio.

The headphones connect wirelessly over Bluetooth 6.1, although they do not support Auracast transmissions — an unfortunate exclusion. There’s also a 3.5mm jack for a wired connection.

Battery life has been increased to up to 50 hours with ANC and 70 hours with ANC off. This is up from 40 hours with ANC and 55 hours without ANC with the Space One headphones. With a five-minute charge the Space 2 get an additional four hours of listening.

Advertisement

The Space 2 will include many of the features found on the Space One. You can use HearID 3.0 to go through a series of sound samples to tune the headphones’ sound to your preferences. It worked well for me on the Space One to get them closer to a sound I liked, with a bit of the edge taken off the higher frequencies. There’s also a sensor that detects when you remove the headphones and stops playback so you don’t miss any of your music or podcast. They once again come with a cloth bag that matches the color of the headphones instead of a case, which is one change I wish Soundcore had made, as the cloth bag doesn’t offer as much protection if you tend to throw your headphones into your backpack or bag.

The Soundcore Space One were among the best budget ANC headphones when they came out, and still hold up to more recent releases. But with the bump in price to over $100 for the Space 2, there’s a bit more expectation on them. ANC performance continues to improve — and products get cheaper — across manufacturers, so the Soundcore Space 2 has some competition from companies like Sony, EarFun, and JLab. If the ANC on the Space 2 stands up to current budget headphones and they still sound as good and are as comfortable as the Space One, you can expect to see the new Soundcore Space 2 on many recommendation lists.

Continue Reading

Technology

Tired of websites blocking your VPN? A dedicated IP fixes that

Published

on

Tired of websites blocking your VPN? A dedicated IP fixes that

NEWYou can now listen to Fox News articles!

If you have ever turned on your VPN and suddenly could not log in to your bank, email, streaming service or work portal, you are not imagining things. In fact, this is one of the most common frustrations VPN users face today.

However, the issue is not that VPNs stopped working. Instead, websites have become far more aggressive about blocking traffic that looks suspicious.

As a result, the way your VPN is built now matters just as much as whether you use one at all.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter    

Advertisement

Shared VPN IPs often trigger red flags, which is why banks, email providers and streaming sites sometimes block access. (Kurt “CyberGuy” Knutsson)

Why websites block many VPN connections

Most VPNs give you a shared IP address. As a result, hundreds or even thousands of people can appear online from the same address at the same time. From a website’s perspective, that traffic pattern raises red flags. When platforms detect too many logins, rapid location changes or unusual activity tied to one IP, they step in quickly. In many cases, they respond by:

  • Blocking access
  • Triggering captchas
  • Requiring extra verification codes
  • Temporarily locking accounts

Meanwhile, you did nothing wrong. Instead, you end up dealing with restrictions caused by other users sharing that same IP address.

What a dedicated IP does differently

With a dedicated IP, you get an address that belongs only to you. Unlike shared VPN connections, no one else uses it.

Each time you connect, you use the same IP address. As a result, you avoid sharing traffic, rotating locations or competing with random users whose activity could trigger blocks.

Because of that consistency, your connection looks much more like a typical home or office internet setup. And that simple difference can dramatically reduce website suspicion and login headaches.

Advertisement

NEW YORK HALTS ROBOTAXI EXPANSION PLAN

A dedicated IP gives you a consistent address that looks more like a normal home connection, reducing captchas and login alerts. (Kurt “CyberGuy” Knutsson)

What a dedicated IP can do that shared VPN IPs usually can’t

That consistency does more than reduce suspicion; it improves how smoothly you access the sites and services you use every day.

Access more websites without blocks

Banks, government portals, healthcare sites, and streaming services are far less likely to block a dedicated IP because it does not show heavy or erratic traffic patterns.

Reduce captchas and security challenges

Those endless “prove you’re human” messages are usually triggered by shared IP abuse. A dedicated IP dramatically reduces them.

Advertisement

Make banking and email logins smoother

Financial institutions and email providers often flag constantly changing IP addresses as suspicious. A dedicated IP stays consistent, so login alerts and lockouts happen far less often.

Support remote work and secure systems

Some employers only allow access from approved IP addresses. Shared VPN IPs cannot be approved. Dedicated IPs can.

Improve streaming reliability

Shared VPN IPs are often the first to get blocked when streaming services crack down. Dedicated IPs are less likely to be flagged because traffic looks normal and predictable.

What a dedicated IP does not do

A dedicated IP:

  • Does not remove encryption
  • Does not expose your identity
  • Does not weaken your privacy

Your traffic remains encrypted, and your real location stays hidden. You simply get a connection that websites trust more.

Who benefits most from a dedicated IP

A dedicated IP is especially helpful if you:

Advertisement
  • Use online banking regularly
  • Travel and access sites from different locations
  • Work remotely
  • Stream often
  • Get tired of captchas and blocked pages
  • Want a VPN that feels normal to use

GOOGLE DISMANTLES 9M-DEVICE ANDROID HIJACK NETWORK

With fewer blocks and smoother logins, a dedicated IP helps your VPN work quietly in the background instead of getting in your way. (Kurt “CyberGuy” Knutsson)

How to choose a VPN that offers a dedicated IP

If you want these benefits, look for a VPN provider that offers a dedicated IP option built directly into its service. Some providers include it in premium plans, while others offer it as an add-on. Either way, the process should be simple. You should be able to select your dedicated IP inside the app without advanced setup or manual configuration. Before signing up, check that the provider also offers strong speeds, reliable uptime and clear privacy policies. A dedicated IP improves access, but overall performance still matters.

 What to look for beyond a dedicated IP

A dedicated IP reduces blocks. However, a quality VPN should also deliver strong security and smooth performance.

Fast, stable connections: Speed matters for streaming, video calls and everyday browsing. Look for providers known for consistent performance.

Wide server coverage: More server locations give you flexibility when traveling and help reduce location errors.

Advertisement

Clear privacy practices: Choose a VPN with a strict no-logs policy and independent audits when possible.

Secure server technology: Modern VPNs often use RAM-based servers that automatically wipe data on reboot.

Easy-to-use apps: Protection should feel simple, not technical. Clean apps across major devices make daily use effortless.

For the best VPN software, see my expert review of the best VPNs for browsing the web privately on your Windows, Mac, Android & iOS devices at Cyberguy.com

Kurt’s key takeaway

If your VPN keeps getting blocked, the problem may not be the VPN itself. It may be the shared IP address behind it. Websites are increasingly aggressive about suspicious traffic. When hundreds of users share the same IP, banks, email providers and streaming platforms take notice. That is when the captchas, verification codes and account lockouts start. A dedicated IP changes that experience. You still get encryption. You still protect your real location. But your connection looks stable and predictable, which helps you avoid constant interruptions.

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Should protecting your privacy really mean fighting with your bank, email, and streaming apps? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter  

Copyright 2026 CyberGuy.com.  All rights reserved.  

Advertisement

Related Article

What Trump's 'ratepayer protection pledge' means for you
Continue Reading

Technology

Polymarket defends its decision to allow betting on war as ‘invaluable’

Published

on

Polymarket defends its decision to allow betting on war as ‘invaluable’
It might be World War III, but at least I won $20. | Image: Polymarket / The Verge

Polymarket has been allowing people to bet on when the US would strike Iran next. Obviously, now that it’s actually happened and people have died, the prediction betting market is feeling some pressure. The site has been at the center of controversy before, including suspicions of insider trading on the Super Bowl halftime show and the capture of Venezuelan President Nicolás Maduro.

In a statement posted on its site, Polymarket defended its decision to allow betting on the potential start of a war, saying that it was an “invaluable” source of news and answers, before taking shots at traditional media and Elon Musk’s X. The statement reads:

Read the full story at The Verge.

Continue Reading

Trending