PULSE NAME
Mamba 2FA: A new contender in the AiTM phishing ecosystem
WHITE AlienVault 2024-10-07 Modified: 2024-11-06
43
IOCs
MEDIUM VOLUME
Mamba 2FA is a newly discovered adversary-in-the-middle (AiTM) phishing kit being sold as phishing-as-a-service (PhaaS). It features capabilities similar to other popular AiTM phishing services, including handling two-step verifications for non-phishing-resistant MFA methods, supporting various authentication systems, and dynamically reflecting organization branding. The kit uses a two-layer infrastructure consisting of link domains and relay servers, leveraging the Socket.IO protocol for communication. Mamba 2FA has been active since at least November 2023 and is commercialized through Telegram. The phishing pages mimic Microsoft 365 services and use sophisticated techniques to evade detection, including HTML attachments with obfuscated content.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Mamba 2FA
Indicators of Compromise (43)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain 10decadesmen.com 2024-10-07
domain 10trioneyue8ss.com 2024-10-07
domain 11beamgools.com 2024-10-07
domain 11cyclesforest.com 2024-10-07
domain 1messisnfarm.com 2024-10-07
domain 2moniunesson.com 2024-10-07
domain 3alphabetjay.com 2024-10-07
domain 4sessionmoon.com 2024-10-07
domain 5poleanalhy.com 2024-10-07
domain 6treesmangle.com 2024-10-07
domain 7motionmansa.com 2024-10-07
domain 88mansession.com 2024-10-07
domain 8boomandool.com 2024-10-07
domain 9cantronnfit.com 2024-10-07
domain ccokies1cakes.com 2024-10-07
domain ccokies2mangoes.com 2024-10-07
domain ccokies3tomatoes.com 2024-10-07
domain copefood.xyz 2024-10-07
domain copelustration.xyz 2024-10-07
domain fivemanchool.com 2024-10-07
domain fiveradio-newbam.com 2024-10-07
domain fourmanchurch.com 2024-10-07
domain fourthmanservice.com 2024-10-07
domain hypexfinancial.com 2024-10-07
domain m1tis-apicookies.com 2024-10-07
domain m2fes-apicookies.com 2024-10-07
domain m3mas-apicookies.com 2024-10-07
domain nine9manforest.com 2024-10-07
domain onemanforest.com 2024-10-07
domain planchereserver.com 2024-10-07
domain seven-oranges.com 2024-10-07
domain sevenmanjungle.com 2024-10-07
domain sithchibb.com 2024-10-07
domain sixmanteams.com 2024-10-07
domain tenetur.top 2024-10-07
domain tenetur.xyz 2024-10-07
domain thirdmandomavis.com 2024-10-07
domain threemanshop.com 2024-10-07
domain tubope.com 2024-10-07
domain twomancake.com 2024-10-07
domain voltampereactive.com 2024-10-07
domain winss0conect.click 2024-10-07
domain winstnet80nss.cfd 2024-10-07