Urgent Gmail Warning: New Astaroth Hack Bypasses Two-Factor Authentication
Urgent Gmail Warning: New Astaroth Hack Bypasses Two-Factor Authentication

Cybersecurity experts have issued a fresh warning to Gmail users after the discovery of a new hacking tool called Astaroth that can bypass two-factor authentication (2FA) to take over email accounts. The tool, which acts as a middleman, intercepts login credentials, verification codes, and cookies in real time, putting over 1.8 billion users at risk.

Astaroth works by tricking victims into clicking a suspicious link that leads to a spoofed login page, mimicking legitimate platforms such as Gmail, Outlook, Yahoo Mail, and AOL. Once the user enters their details, the tool captures usernames, passwords, and 2FA tokens, then forwards them to the real site, allowing the hacker to gain full access without triggering security warnings.

Unlike traditional phishing, Astaroth uses a reverse proxy server that sits between the victim and the genuine service, forwarding all web traffic through the hacker’s system. This enables real-time monitoring of keystrokes and page visits, making it highly effective and difficult to detect. The tool has been sold on the dark web for roughly £1,500 ($2,000), according to researchers at SlashNext.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

To avoid falling victim, users are advised to exercise extreme caution when clicking on links, especially those sent unexpectedly. The only sure way to prevent the attack is to avoid clicking on suspicious links altogether. Action Fraud has urged users to remain vigilant and report any suspicious activity.

Pickt after-article banner — collaborative shopping lists app with family illustration