Mamba 2FA: A new contender in the AiTM phishing ecosystem
ID: 7a8694f7-a7f3-5dbf-8e8a-b50b1c28928e
STIX ID: report--7a8694f7-a7f3-5dbf-8e8a-b50b1c28928e
Feed Name: Sekoia.io Blog
Threat Score
Sekoia TDR details Mamba 2FA, a commercially offered AiTM phishing kit sold via Telegram that uses HTML attachments and Socket.IO websockets to capture credentials, cookies and MFA responses for Microsoft/Entra accounts; the report includes the kit's architecture (link domains, relay servers, proxies), templates, operational timelines, sample IOCs (domains and IPs), detection guidance and evidence of active use since November 2023.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
