New Mamba 2FA bypass service targets Microsoft 365 accounts

Teilen:

An emerging phishing-as-a-service (PhaaS) platform called Mamba 2FA has been observed targeting Microsoft 365 accounts in AiTM attacks using well-crafted login pages.

Additionally, Mamba 2FA offers threat actors an adversary-in-the-middle (AiTM) mechanism to capture the victim’s authentication tokens and bypass multi-factor authentication (MFA) protections on their accounts.

Mamba 2FA is currently sold to cybercriminals for $250/month, which is a competitive price that positions it among the most alluring and fastest-growing phishing platforms in the space.

Discovery and evolution

Mamba 2FA was first documented by Any.Run analysts in late June 2024, but Sekoia reports that it has been tracking activity linked to the phishing platform since May 2024.

Additional evidence shows that Mamba 2FA has been supporting phishing campaigns since November 2023, with the kit being sold on ICQ and later on Telegram.

Following Any.Run’s report of a campaign backed by Mamba 2FA, the operators of the phishing kit made several changes to their infrastructure and methods to increase the stealthiness and longevity of the phishing campaigns.

For example, starting in October, Mamba 2FA introduced proxy servers sourced from IPRoyal, a commercial provider, to mask the IP addresses of relay servers on authentication logs.

Previously, relay servers connected directly to Microsoft Entra ID servers, exposing the IP addresses and making blocks easier.

Link domains used in phishing URLs are now very short-lived and typically rotated weekly to avoid blocklisting by security solutions.

Another change was enhancing HTML attachments used in phishing campaigns with benign filler content to hide a small snippet of JavaScript that triggers the attack, making it harder for security tools to detect.

“Biting” Microsoft 365 users

Mamba 2FA is specifically designed to target users of Microsoft 365 services, including corporate and consumer accounts.

Like other similar PhaaS platforms, it uses proxy relays to conduct AiTM phishing attacks, allowing the threat actors to access one-time passcodes and authentication cookies.

The AiTM mechanism uses the Socket.IO JavaScript library to establish communication between the phishing page and the relay servers at the backend, which in turn communicate with Microsoft’s servers using the stolen data.

Mamba 2FA operational overview
Mamba 2FA operational overview
Source: Sekoia

Mamba 2FA offers phishing templates for various Microsoft 365 services, including OneDrive, SharePoint Online, generic Microsoft sign-in pages, and fake voicemail notifications that redirect to a Microsoft login page.

For enterprise accounts, the phishing pages dynamically assume the targeted organization’s custom login branding, including logos and background images, making the attempt appear more authentic.

Captured credentials and authentication cookies are transmitted to the attacker through a Telegram bot, enabling them to initiate a session immediately.

Mamba 2FA also features sandbox detection, redirecting users to Google 404 webpages when it deduces it’s being under analysis.

Overall, the Mamba 2FA platform is yet another threat to organizations, allowing low-skilled actors to perform highly effective phishing attacks.

To protect against PhaaS operations using AiTM tactics, consider using hardware security keys, certificate-based authentication, geo-blocking, IP allowlisting, device allowlisting, and token lifespan shortening.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:37 am, Jan. 31, 2025
Wetter-Symbol 6°C
L: 6° | H: 7°
overcast clouds
Luftfeuchtigkeit: 92 %
Druck: 1023 mb
Wind: 3 mph S
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:40 am
Sonnenuntergang: 4:47 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
6° | 7°°C 0.8 mm 80% 4 mph 98 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
5° | 7°°C 0 mm 0% 8 mph 94 % 1029 mb 0 mm/h
So. Feb. 02 9:00 pm
Wetter-Symbol
4° | 8°°C 0 mm 0% 8 mph 83 % 1024 mb 0 mm/h
Mo. Feb. 03 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 8 mph 83 % 1026 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
6° | 10°°C 0 mm 0% 11 mph 94 % 1027 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
6° | 6°°C 0.8 mm 80% 2 mph 92 % 1023 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 4 mph 90 % 1023 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 3 mph 93 % 1025 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 98 % 1028 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 5 mph 94 % 1028 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 94 % 1029 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 90 % 1029 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 83 % 1029 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,322.66
-1.02%
Ethereum(ETH)
€3,141.22
1.55%
XRP(XRP)
€2.96
-1.14%
Fesseln(USDT)
€0.96
0.01%
Solana(SOL)
€226.66
-1.95%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.315112
-1.28%
Shiba Inu(SHIB)
€0.000018
0.06%
Pepe(PEPE)
€0.000013
-1.26%
Nach oben scrollen