← Back to Pulse Feed
PULSE DETAIL
Mamba 2FA is an adversary-in-the-middle (AiTM) phishing kit sold as phishing-as-a-service (PhaaS) discovered by Sekoia's Threat Detection & Research (TDR) team in late May 2024. Mamba 2FA mimics Microsoft 365 login pages and uses HTML attachments to trick users into entering their credentials. Once captured, the attackers bypass two-factor authentication (2FA) and gain access to the victim's accounts.
Like other similar PhaaS platforms, it uses proxy relays to conduct AiTM phishing attacks, allowing the threat actors to access one-time passcodes and authentication cookies. The AiTM mechanism uses the Socket.IO JavaScript library to communicate between the phishing page and relay servers, which then communicate with Microsoft's servers using the stolen data.
Captured credentials and cookies are transmitted to the attacker through a Telegram bot, enabling them to initiate a session immediately.
Mamba 2FA also features sandbox detection, redirecting users to Google 404 webpages when under analysis.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| domain | sksexpressplates.com | — | 2025-01-09 | |
| domain | 25green2cook.com | — | 2025-01-09 | |
| domain | davidthairline.be | — | 2025-01-09 | |
| domain | 10decadesmen.com | — | 2025-01-09 | |
| domain | 10trioneyue8ss.com | — | 2025-01-09 | |
| domain | 11beamgools.com | — | 2025-01-09 | |
| domain | 11cyclesforest.com | — | 2025-01-09 | |
| domain | 1messisnfarm.com | — | 2025-01-09 | |
| domain | 2moniunesson.com | — | 2025-01-09 | |
| domain | 3alphabetjay.com | — | 2025-01-09 | |
| domain | 4sessionmoon.com | — | 2025-01-09 | |
| domain | 5poleanalhy.com | — | 2025-01-09 | |
| domain | 6treesmangle.com | — | 2025-01-09 | |
| domain | 7motionmansa.com | — | 2025-01-09 | |
| domain | 88mansession.com | — | 2025-01-09 | |
| domain | 8boomandool.com | — | 2025-01-09 | |
| domain | 9cantronnfit.com | — | 2025-01-09 | |
| domain | ccokies1cakes.com | — | 2025-01-09 | |
| domain | ccokies2mangoes.com | — | 2025-01-09 | |
| domain | ccokies3tomatoes.com | — | 2025-01-09 | |
| domain | copefood.xyz | — | 2025-01-09 | |
| domain | copelustration.xyz | — | 2025-01-09 | |
| domain | drensyoons1sedt.com | — | 2025-01-09 | |
| domain | fivemanchool.com | — | 2025-01-09 | |
| domain | fiveradio-newbam.com | — | 2025-01-09 | |
| domain | fourmanchurch.com | — | 2025-01-09 | |
| domain | fourthmanservice.com | — | 2025-01-09 | |
| domain | grastoonm3vides.com | — | 2025-01-09 | |
| domain | hypexfinancial.com | — | 2025-01-09 | |
| domain | m1tis-apicookies.com | — | 2025-01-09 | |
| domain | m2fes-apicookies.com | — | 2025-01-09 | |
| domain | m3mas-apicookies.com | — | 2025-01-09 | |
| domain | nine9manforest.com | — | 2025-01-09 | |
| domain | onemanforest.com | — | 2025-01-09 | |
| domain | planchereserver.com | — | 2025-01-09 | |
| domain | sandoom2notnt.com | — | 2025-01-09 | |
| domain | seven-oranges.com | — | 2025-01-09 | |
| domain | sevenmanjungle.com | — | 2025-01-09 | |
| domain | sithchibb.com | — | 2025-01-09 | |
| domain | sixmanteams.com | — | 2025-01-09 | |
| domain | tenetur.top | — | 2025-01-09 | |
| domain | tenetur.xyz | — | 2025-01-09 | |
| domain | thirdmandomavis.com | — | 2025-01-09 | |
| domain | threemanshop.com | — | 2025-01-09 | |
| domain | tubope.com | — | 2025-01-09 | |
| domain | twomancake.com | — | 2025-01-09 | |
| domain | voltampereactive.com | — | 2025-01-09 | |
| domain | winss0conect.click | — | 2025-01-09 | |
| domain | winstnet80nss.cfd | — | 2025-01-09 | |
| CVE | CVE-2024-50623 | — | 2025-01-09 | |
| CVE | CVE-2024-55956 | — | 2025-01-09 | |
| domain | merusdesign.com | — | 2025-01-09 | |
| info@windsoracc.net | — | 2025-01-09 | ||
| domain | apremis.com | — | 2025-01-09 | |
| syagi@apremis.com | — | 2025-01-09 | ||
| domain | vivabela.net.br | — | 2025-01-09 | |
| domain | okklink.top | — | 2025-01-09 | |
| domain | lancastervineyard.org | — | 2025-01-09 | |
| cls@lancastervineyard.org | — | 2025-01-09 | ||
| domain | qnkproductions.com | — | 2025-01-09 | |
| hostname | loginmlcrosoftonlino365.pages.dev | — | 2025-01-09 | |
| domain | qcs86.com | — | 2025-02-28 | |
| domain | jan-progtis.com | — | 2025-02-28 |
References (6)
↗ https://blog.sekoia.io/mamba-2fa-a-new-contender-in-the-aitm-phishing-ecosystem/
↗ https://darktrace.com/blog/a-snake-in-the-net-defending-against-aitm-phishing-threats-and-mamba-2fa
↗ https://www.kqlsearch.com/query/Detecting%20Mamba%202fa%20Phishing-as-a-service&cm20830iz01o2mc0py6yvsi2i
↗ https://www.obsidiansecurity.com/blog/mamba-2fa-phishing-kit-why-email-protection-is-not-enough/
↗ https://circleid.com/posts/a-dns-investigation-into-mamba-the-latest-aitm-phishing-player
↗ https://www.bleepingcomputer.com/news/security/new-mamba-2fa-bypass-service-targets-microsoft-365-accounts/