logo

Mamba 2FA: A new contender in the AiTM phishing ecosystem

ID: 7a8694f7-a7f3-5dbf-8e8a-b50b1c28928e

STIX ID: report--7a8694f7-a7f3-5dbf-8e8a-b50b1c28928e

Feed Name: Sekoia.io Blog

Threat Score
72/100

Date Published: 2024-10-07

Date Updated: 2026-04-29

Author: Grégoire Clermont and Sekoia TDR

...
...

Sekoia TDR details Mamba 2FA, a commercially offered AiTM phishing kit sold via Telegram that uses HTML attachments and Socket.IO websockets to capture credentials, cookies and MFA responses for Microsoft/Entra accounts; the report includes the kit's architecture (link domains, relay servers, proxies), templates, operational timelines, sample IOCs (domains and IPs), detection guidance and evidence of active use since November 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.