Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Mamba 2FA

27
Global rank
27 infographic chevron month
Month rank
54 infographic chevron week
Week rank
0
IOCs

Mamba 2FA is an advanced phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) and target Microsoft 365 accounts. It focuses on intercepting authentication flows in real-time and enables threat actors to hijack user sessions and access sensitive systems even when additional security measures are in place.

Phishingkit
Type
Unknown
Origin
1 October, 2023
First seen
17 September, 2026
Last seen

How to analyze Mamba 2FA with ANY.RUN

Type
Unknown
Origin
1 October, 2023
First seen
17 September, 2026
Last seen

IOCs

IP addresses
88.221.169.152
20.190.160.128
188.40.184.212
52.123.243.71
88.221.169.205
48.209.138.168
150.171.28.11
2.20.142.153
142.251.13.101
48.209.138.189
150.171.109.101
104.18.22.222
23.11.41.157
48.192.1.65
172.211.123.248
23.216.77.19
142.251.20.132
150.171.27.11
140.99.208.102
135.232.92.137
Hashes
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
14895bf43ce9b76c0ff4f9aef93dbe8bb6ca496894870cf0c007b189e0cef00e
7ccc7b17bfe01c3c7dd33eff8f80d0b57fc9b175815e766c9c1c1e893725e20f
6c69ce0fe6fab14f1990a320d704fee362c175c00eb6c9224aa6f41108918ca6
5f4229d18e5606330146ee13bdf726e10c1e06cbb15368c47f1ae68abe9ce4ba
ec78ddd4ccf32b5d76ec701a20167c3fbd146d79a505e4fb0421fc1e5cf4aa63
41ce6a7b18364efecced0419b42165d4f86c43643bbe1043014d4142cf86186a
57f81a5fcbd1fefd6ec3cdd525a85b707b4eead532c1b3092daafd88ee9268ec
89082fb05229826bc222f5d22c158235f025f0e6df67ff135a18bd899e13bb8f
e848603b7a73a88e3fe7bffa20e83397f5d1e93e77babb31473cc99e654a27b7
985976b776e729835e047c81d3d731a6c488a6459aa8918dbc8ec808c0bf73a1
Domains
activation-v2.sls.microsoft.com
edge.microsoft.com
client.wns.windows.com
www.bing.com
update.googleapis.com
copilot.microsoft.com
login.live.com
clients2.googleusercontent.com
www.microsoft.com
config.edge.skype.com
crl.microsoft.com
thomas-widmann.com
api.edgeoffer.microsoft.com
go.microsoft.com
google.com
settings-win.data.microsoft.com
ocsp.digicert.com
www.w3schools.com
cdn-icons-png.flaticon.com
oneocsp.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:iwtbcejtoldacry0yvvtikldyteuadkbgldj4i90ubm&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://thomas-widmann.com/3a95wp/i/?c3y9z2vuzxjhbczypuwyjnvpzd1vu0vsmdkwnjiwmjvvmziwnja5mjgmcz1gbw==n0123nzstech@sunmoondata.com
https://thomas-widmann.com/favicon.ico
https://copilot.microsoft.com/c/api/user/eligibility
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d272%2526e%253d1
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://update.googleapis.com/service/update2/json?cup2key=14:xtmbmljt1mhtokwrjp7n6abvepyedyqkryhd3ys65ek&cup2hreq=779d239c0d00a42e5a6e672b3a8d1d3994137b9e2aea259c31cea94a5cc9acf9
https://clients2.googleusercontent.com/crx/blobs/abe5cl52ck7wwbndbvvaem8oys3yhboz1h4zjji-spceoodztoqtbav4glxcdddxfkjcfz5qxdftce2lflmfl4fmgxvilhkmrudcuedenzrbmgjjiqxwnwfy8qwxmtkglheaxlka5bx6yvrdaanj1smxvmii4akl_ln2/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_110_1_0.crx
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
Last Seen at

Recent blog posts

post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 1717
comments 0
post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 3578
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 6642
comments 0

What is Mamba 2FA malware?

Mamba 2FA is part of a growing class of malware that specifically targets multi-factor authentication mechanisms. It is a sophisticated phishing toolkit that leverages AiTM techniques to intercept user credentials and MFA tokens in real time.

The malware, which has been scrutinized and investigated by multiple researchers, including ANY.RUN's analyst team, mimics legitimate Microsoft services, such as OneDrive, SharePoint, and voicemail systems, using highly convincing fake login pages. It is marketed on Telegram and sold for as low as $250 per month, making it accessible to a wide range of threat actors, from novices to seasoned cybercriminals. Its infrastructure has evolved since its first documentation to include proxy servers and regularly updated phishing URLs to evade detection.

It typically operates by injecting malicious code into browsers, intercepting authentication tokens, or manipulating session cookies. Some variants also incorporate phishing components and man-in-the-browser (MitB) capabilities. Mamba 2FA attacks are highly targeted and often occur during high-value transactions or sensitive logins, making them especially dangerous for businesses, financial services, and critical infrastructure.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Mamba 2FA Victimology

Mamba 2FA primarily targets users of Microsoft 365, including both enterprise and consumer accounts. Organizations relying on non-phishing-resistant MFA methods, such as one-time passwords (OTPs) and app notifications, are particularly vulnerable.

Industries with heavy Microsoft 365 usage, such as finance, healthcare, and technology, are prime targets due to their valuable data and reliance on cloud-based services. The platform’s ability to customize phishing pages to reflect corporate branding makes it especially effective against employees who may not recognize the signs of phishing.

Geographically, campaigns have been observed in Europe, North America, and parts of Asia, often coinciding with politically or economically motivated attacks.

What Mamba Can Do to User Device

While Mamba 2FA itself is not a traditional malware that installs malicious code on endpoint devices, its impact is significant. Once a user enters credentials and MFA tokens on a phishing page, attackers gain immediate access to the victim’s account. This can lead to:

  • Unauthorized Access: Attackers can log into Microsoft 365 accounts, accessing sensitive emails, files, and data stored in OneDrive or SharePoint.

  • Data Theft: Sensitive information, such as financial records or intellectual property, can be exfiltrated.

  • Account Takeover: Attackers can change account settings, lock out legitimate users, or use the account for further malicious activities, such as sending phishing emails to other users.

  • Lateral Movement: Compromised accounts can serve as entry points for broader network attacks, potentially leading to ransomware or data breaches.

How Mamba 2FA Threatens Businesses and Organizations

Mamba 2FA poses a severe threat to businesses due to its ability to bypass MFA, a cornerstone of modern cybersecurity. The platform’s low cost and ease of use democratize advanced phishing capabilities, enabling even low-skill attackers to execute sophisticated campaigns. Key threats include:

  • Financial Loss: Stolen data or compromised accounts can lead to direct financial theft or costly ransomware attacks.
  • Reputational Damage: Data breaches erode customer trust and can lead to regulatory penalties.
  • Operational Disruption: Account takeovers can disrupt business operations, particularly if critical systems or communications are compromised.
  • Scalability: As a PhaaS platform, Mamba 2FA allows attackers to target multiple organizations simultaneously, increasing the scale and impact of attacks.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

How Does Mamba 2FA Function?

Typically, this malware:

  • Uses phishing emails or compromised websites to deliver the malware.
  • Hooks into the browser or network stack to monitor authentication flows.
  • In real-time, intercepts or relays 2FA codes back to the attacker.
  • Enables session replay or steals authentication cookies to access targets without triggering 2FA.

Core operations are organized through a two-layer infrastructure:

  1. Link Domains: They host phishing pages that mimic Microsoft services, using Base64-encoded parameters to customize the page for specific targets. Invalid parameters trigger redirection to benign error pages (e.g., Google 404) to evade detection.
  2. Relay Servers: Powered by Socket.IO, these servers facilitate real-time communication between the phishing page and Microsoft’s authentication servers, intercepting credentials and MFA tokens. Attackers use stolen data to authenticate as the victim, bypassing MFA protections.

The platform supports non-phishing-resistant MFA methods, integrates with Entra ID, AD FS, and third-party SSO providers, and instantly transmits stolen credentials and cookies via Telegram bots. It also employs sandbox detection to block automated security scans, enhancing its stealth.

Mamba 2FA Typical Attack Chain

The primary attack vector for Mamba 2FA is phishing emails, which serve as the initial point for luring victims outside the secure perimeter of corporate environments. The HTML attachments contain obfuscated JavaScript code that redirects users to phishing pages, often hosted on services like Cloudflare R2 or IPFS.

Common lures include:

  • Voicemail notifications, often with an SVG file.

  • File access notifications for OneDrive/SharePoint.

  • Payment or invoice receipts.

  • Password expiration notices.

    Each of these delivery methods can be detonated and effectively analyzed in ANY.RUN’s Sandbox service using its ML functionality.

Sandbox analysis of Mamba 2FA sample with a voice message notification

Mamba 2FA malware analysis in the Sandbox
Mamba 2FA analysis in the Sandbox

Sandbox analysis of Mamba 2FA sample with a password expiration notice

Mamba 2FA malware analysis in the Sandbox
Another Mamba 2FA sample detonated in the Sandbox

Mamba 2FA uses a fingerprinting mechanism to filter users before redirecting to either a phishing or benign page. After clicking the link from the phishing email, the victim lands on a filtering page that collects device and browser data. This data is sent to a server that decides whether to redirect the user to a phishing page mimicking Microsoft services or to a safe dead-end page. Fingerprinting transmission can be tracked through the Suricata rule "ET PHISHING Javascript Browser Fingerprinting POST Request".

Fingerprinting request in Mamba 2FA activity
Fingerprinting request in Mamba 2FA activity

After passing filtering, the user is redirected to a phishing page created based on templates that mimic Microsoft authorization pages, including OneDrive and SharePoint. For corporate accounts, Mamba 2FA pulls backgrounds and icons corresponding to the target organization's branding using legitimate Microsoft CDNs, which increases the page's credibility. The phishing page URL typically contains a domain/base64 pattern, where parameters such as IP address, victim's email address, service identifier (e.g., Office 365), campaign, or unique user identifier are encoded in Base64 format for masking and complicating analysis.

In implementing the "Adversary-in-the-Middle" (AiTM) technique, Mamba 2FA uses the Socket.IO JavaScript library to organize real-time communication through WebSocket, which is one of the main differences from other phishing kits.

Gathering Threat Intelligence on Mamba 2FA malware

Threat intelligence is critical in combating Mamba 2FA by providing real-time insights into its infrastructure, tactics, and IOCs. It enables organizations to:

  • Identify Attack Patterns: Recognize phishing email signatures, URL structures, and relay server IPs.
  • Update Defenses: Incorporate IOCs into firewalls, intrusion detection systems, and email filters.
  • Proactive Response: Anticipate and block emerging threats by tracking Mamba 2FA’s evolution on platforms like Telegram.
  • Collaboration: Share intelligence with industry peers to improve collective defenses.

Services such as Threat Intelligence Lookup from ANY.RUN allow identifying and blocking Mamba2FA infrastructure, including domains and IPs, at the network perimeter.

Start gathering IOCs and behavioral data with the malware name search request to Threat Intelligence Lookup:

threatName:"mamba"

Mamba 2 FA samples found via TI Lookup Mamba 2 FA samples recently analyzed in the Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Mamba 2FA represents a growing class of post-authentication threats capable of undermining modern security infrastructures. As more organizations adopt MFA, attackers evolve to bypass it. Understanding how Mamba 2FA works and using threat intelligence to detect and disrupt its lifecycle is essential for proactive defense. Organizations must pair robust technical controls with actionable data to stay ahead of these advanced threats.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

EvilTokens screenshot
EvilTokens
eviltokens
EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.
Read More
Remote Access Trojan screenshot
Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.
Read More
DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
Grandoreiro screenshot
Grandoreiro
grandoreiro
Grandoreiro is a Latin American banking trojan first observed in 2016. It targets mostly Spanish-speaking countries, such as Brazil, Spain, Mexico and Peru. This malware is operated as a Malware-as-a-Service (MaaS), which makes it easily accessible for cybercriminals. Besides, it uses advanced techniques to evade detection.
Read More
Razr screenshot
Razr
razr
Razr is a destructive ransomware that infiltrates systems to encrypt files, rendering them inaccessible to users. It appends the ".razr" extension to the encrypted files and drops a ransom note, typically named "README.txt," instructing victims on how to pay the ransom to obtain the decryption key. The malware often spreads through phishing emails with malicious attachments or by exploiting vulnerabilities in software and operating systems. Razr employs strong encryption algorithms, making it challenging to decrypt files without the attackers' key.
Read More