Target Industry
Indiscriminate
Overview
Security researchers have detected a new Adversary in the Middle (AitM) Phishing as a Service (PhaaS) platform called Mamba 2FA, which has been observed targeting Microsoft 365 accounts.
Mamba 2FA is a low-cost and low-complexity toolkit which enables threat actors to conduct email phishing campaigns that mimic Microsoft 365 login pages. The false login pages capture authentication tokens which bypass multi-factor authentication (MFA).
Impact
It has been assessed that the Mamba 2FA kit poses a significant risk to organisations due to its ability to bypass non-phishing resistant MFA methods, such as one-time codes and application notifications. This makes it easier for threat actors to gain unauthorised access to accounts that rely on these MFA methods. These phishing attempts are more convincing and persistent since the threat actors are reflecting the custom branding of the company being targeted.
Exploitation
The Mamba 2FA kit is exploited in several ways to bypass MFA to steal sensitive information. These exploits are:
- AiTM – the threat actor sits between the user and the legitimate authentication service. They then intercept and relay MFA credentials, allowing unauthorised access to the accounts even if MFA is enabled
- Convincing phishing pages – mimicking legitimate login portals, such as Microsoft 365. These are dynamically adapted to reflect the branding of the targeted organisation, making the attack more convincing and harder to detect – which leads on to the capture of the user’s credentials and MFA tokens
- Socket.IO (a JavaScript library) – to maintain real-time communication between the phishing page and the backend server, ensuring that the intercepted credentials are immediately relayed
- Telegram (a cloud-based instant messaging application) – the stolen credentials are sent directly to threat actors providing near-instant access to compromised accounts
- HTML attachments – with obfuscated content to evade detection by security systems.
Because Mamba 2FA kit is sold as a PhaaS on platforms like Telegram for around $250 per month it is widely accessible to a range of threat actors.
Containment, Mitigations & Remediations
To contain Mamba 2FA kit, isolate affected systems to prevent further spread, block internet protocols (IPs) and domains which are associated with Mamba 2FA kit phishing campaigns. Temporarily disable accounts that have been compromised to prevent unauthorised access.
Indicators of Compromise
Mamba 2FA kit phishing pages can be seen imitating OneDrive, a secure SharePoint link, the generic Microsoft sign-in page and voice mail, leading the user to a generic Microsoft sign-in page. These phishing pages have a URL of https://{domain}/{m,n,o}/?{Base64 string} with the page only being displayed if there is a valid Base64 parameter. It should be noted that the phishing kit is able to detect sandboxes, and if this happens the user is redirected to a page not found at https[://]google[.]com/404/.
The user’s email address can be found at the end of the phishing page URL. Some examples of this are:
- https[://]tubope[.]com/n/?c3Y9bz…[email protected]
- https[://]tubope[.]com/n/?c3Y9bz…TI1NTk=N0123Nc2F0eWFuQG1pY3Jvc29mdC5jb20=
- https[://]tubope[.]com/n/?c3Y9bz…TI1NTk=#[email protected]
- https[://]tubope[.]com/n/?c3Y9bz…TI1NTk=#c2F0eWFuQG1pY3Jvc29mdC5jb20=
Threat Landscape
More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. Due to Mamba 2FA’s complexity, it is a concerning threat because of its advanced capabilities and widespread use.
Threat Group
The specific threat group behind the Mamba 2FA kit has not been publicly identified.
TTPs
- T1598 – Phishing for Information
- T1589 – Gather Victim Identity Information
- T1111 – Multi-Factor Authentication Interception
- T0830 – Adversary-in-the-Middle
Further Information
Beware the Bite of Mamba 2FA: This Phishing Kit Bypasses 2FA (securityonline.info)
Mamba 2FA: A new contender in the AiTM phishing ecosystem – Sekoia.io Blog
New Mamba 2FA bypass service targets Microsoft 365 accounts (bleepingcomputer.com)













