New Mamba 2FA bypass service targets Microsoft 365 accounts
ID: 46e11401-457c-593d-ae68-f6b5705d9273
STIX ID: report--46e11401-457c-593d-ae68-f6b5705d9273
Feed Name: Bleeping Computer
Mamba 2FA is an emerging phishing-as-a-service platform that conducts AiTM attacks against Microsoft 365 users to capture credentials and authentication cookies and bypass MFA. The kit—observed since late 2023 and tracked by analysts in mid-2024—is sold to criminals, uses proxy relays, dynamic branding, Socket.IO communication, Telegram-based exfiltration, and sandbox detection to increase stealth and effectiveness; the report also outlines mitigations such as hardware keys, certificate-based auth, geo/IP/device allowlisting, and shortening token lifespans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
