Mamba 2FA Cybercrime Kit Targets Microsoft 365 Users
ID: a6e756e0-0ca1-5be8-b4f9-19e86829d337
STIX ID: report--a6e756e0-0ca1-5be8-b4f9-19e86829d337
Feed Name: Dark Reading
Date Published: 2024-10-09
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Sekoia researchers report a commercial phishing-as-a-service named Mamba 2FA that targets Microsoft 365 users with AitM phishing pages imitating OneDrive, SharePoint, Microsoft sign-in, or voicemail links; it mirrors enterprise branding, bypasses one-time-code and push 2FA, supports Entra ID/AD FS/SSO and consumer accounts, and immediately exfiltrates harvested credentials and cookies to an attacker-controlled Telegram bot. The kit has been offered on underground channels since at least March (used in campaigns since November 2023) and is sold for about $250/month.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
