Salty2FA and Tycoon2FA Phishing Kits Attacking Enterprise Users to Steal Login Credentials
ID: a41b452c-f1c9-5a4b-bbd9-8d3772e2a69f
STIX ID: report--a41b452c-f1c9-5a4b-bbd9-8d3772e2a69f
Feed Name: cybersecurityNews.com
Threat Score
A newly observed hybrid phishing campaign blends Salty2FA and Tycoon2FA phishing kits—likely operated or consolidated under APT Storm-1747—using Salty2FA trampoline scripts with a hardcoded fallback to Tycoon2FA when domains fail, reproducing Tycoon2FA’s execution chain and facilitating MFA bypass via AiTM; SOCs should treat both kits as a single threat cluster and correlate delivery and network indicators to detect these resilient, multi-stage attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
