A new phishing-as-a-service (PhaaS) platform, called Mamba 2FA, targets Microsoft 365 accounts in AiTM attacks and allows attackers to steal victim authentication tokens and bypass multi-factor authentication (MFA) protections on their accounts.

The Mamba 2FA service is being sold to cybercriminals for $250/month, a tempting price, which could help the platform become very popular.
Mamba 2FA was first reported by Any.Run in late June 2024. However, Sekoia says it has been monitoring activity linked to the phishing platformsince May 2024.
See also: INTERPOL: Eight people arrested for phishing & romance scams
There is also evidence that Mamba 2FA was supporting phishing campaigns as early as November 2023, and the phishing kit was being sold on ICQ and later on Telegram.
Following Any.Run's report of a campaign supported by the service , the phishing kit operators made several changes to their infrastructure and methods.
For example, since October, Mamba 2FA has been introducing proxy servers from IPRoyal, a commercial provider. The operators' goal was to hide the IP addresses of the relay servers in the authentication logs.
Previously, relay servers connected directly to Microsoft Entra ID servers, exposing IP addresses and facilitating blocks.
Another change has to do with Link domains in phishing URLs. They are now short-lived and usually rotate on a weekly basis to avoid being blocked by security.
See also: Spear-phishing campaign infects recruiters with More_eggs backdoor
Finally, operators have improved the HTML attachments used in phishing attacks. They also use legitimate filler content to hide a small snippet of JavaScript that triggers the attack. This makes it harder for security tools to detect.
Mamba 2FA targets Microsoft 365 accounts
The Mamba 2FA service is specifically designed to target Microsoft 365 service users (with corporate and personal accounts)
Like other PhaaS platforms, it uses proxy relays to conduct AiTM phishing attacks, allowing attackers to access one-time passwords and authentication cookies.
The AiTM mechanism uses the Socket.IO JavaScript to establish communication between the phishing page and relay servers on the backend. These in turn communicate with Microsoft servers using the stolen data.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
According to the researchers, Mamba 2FA offers cybercriminals a variety of phishing templates, suitable for various Microsoft 365 services, such as OneDrive, SharePoint Online, and general Microsoft. There are also fake voicemail notifications to redirect to a supposed Microsoft sign-in page.
To target corporate accounts, phishing pages use the targeted organization's branding, logos, and background imagesto make the phishing pages appear authentic.
See also: Zimperium: Mobile devices targeted by phishing attacks

The stolen credentials and authentication cookies are transmitted to the attacker via a Telegram bot, allowing him to immediately start a session.
The Mamba 2FA phishing service also features sandbox detection, redirecting users to Google 404 pages if it sees that it is under analysis.
In conclusion, this platform is a new threat to users and organizations, since it can allow almost anyone to carry out effective phishing attacks.
Additionally, Mamba 2FA allows cybercriminals to bypass two-factor authentication (2FA), which increases the chances of successful attacks. This puts Microsoft 365 account users at greater risk.
These attacks can lead to the loss of confidential data, such as personal information, access credentials, and corporate data. In addition, there can be financial losses, as phishing attacks can be used to trick victims into handing over their credentials for bank accounts or other payment services.
To protect against PhaaS platforms that use AiTM tactics, the use of hardware security keys, certificate-based authentication , geo-blocking, the use of an IP allowlisting, a device allowlisting, and token lifespan shortening is recommended.
Source: www.bleepingcomputer.com
