PULSE NAME
Mamba 2FA PhaaS
WHITE Mamba 2FA v0od0o.exe 2025-01-09 Modified: 2025-02-28
63
IOCs
HIGH VOLUME
Mamba 2FA is an adversary-in-the-middle (AiTM) phishing kit sold as phishing-as-a-service (PhaaS) discovered by Sekoia's Threat Detection & Research (TDR) team in late May 2024. Mamba 2FA mimics Microsoft 365 login pages and uses HTML attachments to trick users into entering their credentials. Once captured, the attackers bypass two-factor authentication (2FA) and gain access to the victim's accounts. Like other similar PhaaS platforms, it uses proxy relays to conduct AiTM phishing attacks, allowing the threat actors to access one-time passcodes and authentication cookies. The AiTM mechanism uses the Socket.IO JavaScript library to communicate between the phishing page and relay servers, which then communicate with Microsoft's servers using the stolen data. Captured credentials and cookies are transmitted to the attacker through a Telegram bot, enabling them to initiate a session immediately. Mamba 2FA also features sandbox detection, redirecting users to Google 404 webpages when under analysis.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Mamba 2FA
Indicators of Compromise (63)
All domain CVE email hostname
TYPEINDICATORDESCRIPTIONCREATED
domain sksexpressplates.com 2025-01-09
domain 25green2cook.com 2025-01-09
domain davidthairline.be 2025-01-09
domain 10decadesmen.com 2025-01-09
domain 10trioneyue8ss.com 2025-01-09
domain 11beamgools.com 2025-01-09
domain 11cyclesforest.com 2025-01-09
domain 1messisnfarm.com 2025-01-09
domain 2moniunesson.com 2025-01-09
domain 3alphabetjay.com 2025-01-09
domain 4sessionmoon.com 2025-01-09
domain 5poleanalhy.com 2025-01-09
domain 6treesmangle.com 2025-01-09
domain 7motionmansa.com 2025-01-09
domain 88mansession.com 2025-01-09
domain 8boomandool.com 2025-01-09
domain 9cantronnfit.com 2025-01-09
domain ccokies1cakes.com 2025-01-09
domain ccokies2mangoes.com 2025-01-09
domain ccokies3tomatoes.com 2025-01-09
domain copefood.xyz 2025-01-09
domain copelustration.xyz 2025-01-09
domain drensyoons1sedt.com 2025-01-09
domain fivemanchool.com 2025-01-09
domain fiveradio-newbam.com 2025-01-09
domain fourmanchurch.com 2025-01-09
domain fourthmanservice.com 2025-01-09
domain grastoonm3vides.com 2025-01-09
domain hypexfinancial.com 2025-01-09
domain m1tis-apicookies.com 2025-01-09
domain m2fes-apicookies.com 2025-01-09
domain m3mas-apicookies.com 2025-01-09
domain nine9manforest.com 2025-01-09
domain onemanforest.com 2025-01-09
domain planchereserver.com 2025-01-09
domain sandoom2notnt.com 2025-01-09
domain seven-oranges.com 2025-01-09
domain sevenmanjungle.com 2025-01-09
domain sithchibb.com 2025-01-09
domain sixmanteams.com 2025-01-09
domain tenetur.top 2025-01-09
domain tenetur.xyz 2025-01-09
domain thirdmandomavis.com 2025-01-09
domain threemanshop.com 2025-01-09
domain tubope.com 2025-01-09
domain twomancake.com 2025-01-09
domain voltampereactive.com 2025-01-09
domain winss0conect.click 2025-01-09
domain winstnet80nss.cfd 2025-01-09
CVE CVE-2024-50623 2025-01-09
CVE CVE-2024-55956 2025-01-09
domain merusdesign.com 2025-01-09
email info@windsoracc.net 2025-01-09
domain apremis.com 2025-01-09
email syagi@apremis.com 2025-01-09
domain vivabela.net.br 2025-01-09
domain okklink.top 2025-01-09
domain lancastervineyard.org 2025-01-09
email cls@lancastervineyard.org 2025-01-09
domain qnkproductions.com 2025-01-09
hostname loginmlcrosoftonlino365.pages.dev 2025-01-09
domain qcs86.com 2025-02-28
domain jan-progtis.com 2025-02-28