Target Industry

Indiscriminate

Overview 

Security researchers have detected a new Adversary in the Middle (AitM) Phishing as a Service (PhaaS) platform called Mamba 2FA, which has been observed targeting Microsoft 365 accounts.  

Mamba 2FA is a low-cost and low-complexity toolkit which enables threat actors to conduct email phishing campaigns that mimic Microsoft 365 login pages. The false login pages capture authentication tokens which bypass multi-factor authentication (MFA).  

Impact 

It has been assessed that the Mamba 2FA kit poses a significant risk to organisations due to its ability to bypass non-phishing resistant MFA methods, such as one-time codes and application notifications. This makes it easier for threat actors to gain unauthorised access to accounts that rely on these MFA methods. These phishing attempts are more convincing and persistent since the threat actors are reflecting the custom branding of the company being targeted.  

Exploitation 

The Mamba 2FA kit is exploited in several ways to bypass MFA to steal sensitive information. These exploits are: 

  • AiTM – the threat actor sits between the user and the legitimate authentication service. They then intercept and relay MFA credentials, allowing unauthorised access to the accounts even if MFA is enabled 
  • Convincing phishing pages – mimicking legitimate login portals, such as Microsoft 365. These are dynamically adapted to reflect the branding of the targeted organisation, making the attack more convincing and harder to detect – which leads on to the capture of the user’s credentials and MFA tokens 
  • Socket.IO (a JavaScript library) – to maintain real-time communication between the phishing page and the backend server, ensuring that the intercepted credentials are immediately relayed 
  • Telegram (a cloud-based instant messaging application) – the stolen credentials are sent directly to threat actors providing near-instant access to compromised accounts 
  • HTML attachments – with obfuscated content to evade detection by security systems. 

Because Mamba 2FA kit is sold as a PhaaS on platforms like Telegram for around $250 per month it is widely accessible to a range of threat actors. 

 Containment, Mitigations & Remediations 

To contain Mamba 2FA kit, isolate affected systems to prevent further spread, block internet protocols (IPs) and domains which are associated with Mamba 2FA kit phishing campaigns. Temporarily disable accounts that have been compromised to prevent unauthorised access. 

Indicators of Compromise 

Mamba 2FA kit phishing pages can be seen imitating OneDrive, a secure SharePoint link, the generic Microsoft sign-in page and voice mail, leading the user to a generic Microsoft sign-in page. These phishing pages have a URL of https://{domain}/{m,n,o}/?{Base64 string} with the page only being displayed if there is a valid Base64 parameter. It should be noted that the phishing kit is able to detect sandboxes, and if this happens the user is redirected to a page not found at https[://]google[.]com/404/. 

The user’s email address can be found at the end of the phishing page URL. Some examples of this are: 

  • https[://]tubope[.]com/n/?c3Y9bz…TI1NTk=N0123Nc2F0eWFuQG1pY3Jvc29mdC5jb20= 
  • https[://]tubope[.]com/n/?c3Y9bz…TI1NTk=#c2F0eWFuQG1pY3Jvc29mdC5jb20= 

Threat Landscape 

More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. Due to Mamba 2FA’s complexity, it is a concerning threat because of its advanced capabilities and widespread use. 

Threat Group 

The specific threat group behind the Mamba 2FA kit has not been publicly identified. 

TTPs 

  • T1598 – Phishing for Information 
  • T1589 – Gather Victim Identity Information 
  • T1111 – Multi-Factor Authentication Interception 
  • T0830 – Adversary-in-the-Middle 

Further Information 

Beware the Bite of Mamba 2FA: This Phishing Kit Bypasses 2FA (securityonline.info)

Mamba 2FA: A new contender in the AiTM phishing ecosystem – Sekoia.io Blog

New Mamba 2FA bypass service targets Microsoft 365 accounts (bleepingcomputer.com)

Microsoft Detects Growing Use of File Hosting Services in Business Email Compromise Attacks (thehackernews.com) 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content