logo

Mamba 2FA Cybercrime Kit Targets Microsoft 365 Users

ID: a6e756e0-0ca1-5be8-b4f9-19e86829d337

STIX ID: report--a6e756e0-0ca1-5be8-b4f9-19e86829d337

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-10-09

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Sekoia researchers report a commercial phishing-as-a-service named Mamba 2FA that targets Microsoft 365 users with AitM phishing pages imitating OneDrive, SharePoint, Microsoft sign-in, or voicemail links; it mirrors enterprise branding, bypasses one-time-code and push 2FA, supports Entra ID/AD FS/SSO and consumer accounts, and immediately exfiltrates harvested credentials and cookies to an attacker-controlled Telegram bot. The kit has been offered on underground channels since at least March (used in campaigns since November 2023) and is sold for about $250/month.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.