PULSE NAME
Major August 2025 Cyber Attacks: 7-Stage Tycoon2FA Phishing, New ClickFix Campaign, and Salty2FA
WHITE Storm-1575 AlienVault 2025-08-26 Modified: 2025-09-29
24
IOCs
MEDIUM VOLUME
In August 2025, significant cyber attacks emerged, including a 7-stage Tycoon2FA phishing campaign targeting government, military, and financial institutions across the US, UK, Canada, and Europe. The attack uses multiple verification steps to evade security systems. A new ClickFix campaign delivered the Rhadamanthys Stealer using PNG steganography, indicating increased sophistication in payload delivery. Salty2FA, a new Phishing-as-a-Service framework attributed to Storm-1575, was discovered targeting Microsoft 365 accounts globally, capable of bypassing various 2FA methods. These attacks demonstrate the evolution of phishing kits and stealers, emphasizing the need for behavioral analysis and real-time threat intelligence in cybersecurity defenses.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Tycoon2FA Rhadamanthys Stealer Salty2FA
Indicators of Compromise (24)
All domain hostname URL
TYPEINDICATORDESCRIPTIONCREATED
domain culturabva.es 2025-08-26
domain dvlhpbxlmmi.es 2025-08-26
domain flaxergaurds.com 2025-08-26
domain innovationsteams.com 2025-08-26
domain loanauto.cloud 2025-08-26
domain marketplace24ei.ru 2025-08-26
domain pyfao.es 2025-08-26
domain spaijo.es 2025-08-26
domain temopix.com 2025-08-26
domain vnositel-bg.com 2025-08-26
domain wetotal.net 2025-08-26
domain yurikamome.com 2025-08-26
domain zerontwoposh.live 2025-08-26
hostname telephony.nexttradeitaly.com 2025-08-26
URL https://microsofstlive.fare.com.de/JmJfd 2025-08-28
URL https://curie77.fr/?download=1&kccpid=2339&kcccount=https://kkvl.legends.com.de/be2N0 2025-08-28
URL https://marketplace24ei.ru// 2025-08-28
URL https://marketplace24ei.ru/790628.php 2025-08-28
URL https://telephony.nexttradeitaly.com/SSSuWBTmYwu/ 2025-08-28
domain curie77.fr 2025-08-28
domain fbetlixgee.eu 2025-08-28
domain innovationsteams.com 2025-08-28
domain marketplace24ei.ru 2025-08-28
hostname telephony.nexttradeitaly.com 2025-08-28