Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Salty 2FA

79
Global rank
149 infographic chevron month
Month rank
109 infographic chevron week
Week rank

Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.

Phishingkit
Type
Unknown
Origin
1 June, 2025
First seen
6 October, 2026
Last seen

How to analyze Salty 2FA with ANY.RUN

Type
Unknown
Origin
1 June, 2025
First seen
6 October, 2026
Last seen

IOCs

IP addresses
2.21.20.144
104.17.112.233
150.171.28.11
141.101.90.105
74.178.240.61
48.209.138.168
23.11.41.157
48.209.138.189
74.125.250.129
150.171.109.99
150.171.27.11
20.190.159.131
92.122.215.96
48.192.1.65
20.165.94.54
23.207.210.132
104.18.22.222
104.19.230.21
104.19.229.21
188.114.97.3
Hashes
bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
fac0a85e4f5907c8036b0052214b777ddbacea9420e5903526272dc76bd4c7b6
8232c450f967d7f2f22c54582f0667f4c033ae62e6d450ff8a35c47486249443
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
7852fce59c67ddf1d6b8b997eaa1adfac004a9f3a91c37295de9223674011fba
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
14895bf43ce9b76c0ff4f9aef93dbe8bb6ca496894870cf0c007b189e0cef00e
7ccc7b17bfe01c3c7dd33eff8f80d0b57fc9b175815e766c9c1c1e893725e20f
6c69ce0fe6fab14f1990a320d704fee362c175c00eb6c9224aa6f41108918ca6
5f4229d18e5606330146ee13bdf726e10c1e06cbb15368c47f1ae68abe9ce4ba
ec78ddd4ccf32b5d76ec701a20167c3fbd146d79a505e4fb0421fc1e5cf4aa63
Domains
stun.l.google.com
snip.ly
edge.microsoft.com
aadcdn.msftauth.net
update.googleapis.com
stun1.l.google.com
challenges.cloudflare.com
crl.microsoft.com
identity.nel.measure.office.net
api.hcaptcha.com
www.bing.com
login.microsoft.com
edge-consumer-static.azureedge.net
notifications.workers-deskservices.com
cfc2a8af471e.w.hcaptcha.com
pdcu3.r.ag.d.sendibm3.com
google.com
client.wns.windows.com
config.edge.skype.com
nexusrules.officeapps.live.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:0z351z64hvrd5durdbo9d1phqp9i05qfoef-asb3h-i&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://copilot.microsoft.com/c/api/user/eligibility
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1791286277&lafgdate=0
https://pdcu3.r.ag.d.sendibm3.com/mk/cl/f/sh/1f8jikxwhgaqlovena8v0lhxgd/gsfka0bjo6m5
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://sibautomation.com/cm.html?id=12330763
https://in-automate.brevo.com/cm?uuid=88f58000-8566-4a3f-937c-9d88a50aaef3&client_id=12330763&trans=0&user_id=1
https://tinyurl.com/2dsfcw8u
https://tinyurl.com/2cnxuz9j
https://pdcu3.r.ag.d.sendibm3.com/mk/cl/f/sh/1f8jikxwhgaqlovena8v0lhxgd/5rnrheyfhcfh
https://pdcu3.r.ag.d.sendibm3.com/favicon.ico
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1791286277&lafgdate=0
https://kalipdunyasi.com.tr/?num=1-1&link=https://employeedesksteamwo84253.myclickfunnels.com/5d40839a17
https://kalipdunyasi.com.tr/?num=1-1&link=https://snip.ly/u36wtl
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1024
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2815
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10289
comments 0

Salty 2FA Malware: When Hackers Turn Authentication Against You

Key Takeaways

  1. MFA Alone Is Not Sufficient Protection. Salty 2FA can bypass six different types of multi-factor authentication including SMS codes, push notifications, voice calls, and authenticator app OTPs. Organizations must transition to phishing-resistant authentication methods like FIDO2/WebAuthn hardware security keys that cannot be intercepted through man-in-the-middle attacks.

  2. Behavioral Detection Outperforms Static Signatures. Indicators like domains and IP addresses change constantly as Salty 2FA rotates infrastructure, making signature-based detection unreliable. The most effective detection focuses on behavioral patterns that remain consistent: the unique .com + .ru domain combinations, multi-stage execution chains, Cloudflare service usage patterns, and encoded data exfiltration methods.

  3. Targeted Industries Face Elevated Risk. Salty 2FA demonstrates clear targeting preferences for high-value sectors including financial services, energy infrastructure, logistics, telecommunications, government, and consulting firms.

  4. Multi-Layered Defense Is Essential. No single security control can prevent Salty 2FA attacks. Effective defense requires multiple overlapping layers: advanced email security with link sandboxing, DNS filtering with pattern-based detection, phishing-resistant authentication, endpoint detection and response, user behavior analytics, security awareness training, and threat intelligence integration.

  5. Threat Intelligence Enables Proactive Defense. Early warning about the framework's emergence, understanding of its behavioral patterns, context about targeting and techniques, and continuous IOC feeds enable organizations to implement protections before becoming victims. Leverage Threat Intelligence Lookup to explore fresh contextual threat data.

  6. User Awareness Remains Critical. Trained users who can recognize phishing attempts, verify URLs before entering credentials, report suspicious emails, and understand the importance of not approving unexpected MFA requests provide essential human intelligence and early warning.

Enable users to check suspicious messages and attachments in ANY.RUN’s Interactive Sandbox:

PDF document detected as phishing and Salty 2FA by ANY.RUN PDF document recognized as phishing and Salty 2FA by ANY.RUN

  1. Interactive Sandbox Analysis Is Necessary for Detection. Traditional static analysis fails against Salty 2FA's extensive obfuscation, anti-analysis mechanisms, and multi-stage execution. Interactive sandbox environments that simulate user interactions and capture real-time behavior are essential for understanding how the framework operates, extracting IOCs, mapping infrastructure, and developing effective detection rules.

What is Salty 2FA Malware?

Salty 2FA represents the evolution of phishing kits, blending enterprise-grade sophistication with the accessibility of a service model. Discovered by ANY.RUN’s analysts in mid-2025, the framework draws inspiration from groups like Storm-1575 (known for the Dadsec platform) and Storm-1747 (behind Tycoon 2FA) but stands distinct in its infrastructure and techniques.

The name "Salty 2FA" derives from its "salted" payloads — heavily obfuscated code that distinguishes it from other phishing kits during analysis.

Unlike traditional credential stealers that focus on static passwords, Salty 2FA specifically targets time-based one-time passwords (TOTPs) and push-based 2FA systems. It intercepts or manipulates the authentication process, allowing adversaries to impersonate legitimate users in real time.

Salty 2FA is often deployed in multi-stage attacks, where it follows initial compromise through phishing, malicious attachments, or fake authentication apps. Once inside, it hooks into browser sessions or mobile apps to intercept verification tokens and authentication prompts.

The malware’s modular architecture enables it to adapt to different environments from individual endpoints to enterprise networks, making it a versatile and persistent threat.

The framework can validate stolen credentials in real-time, intercept multiple types of two-factor authentication methods, and maintain persistent communication with command-and-control servers through an encoded data exfiltration system.

The entire operation is protected by multiple layers of anti-analysis mechanisms, including JavaScript-based anti-debugging features, keyboard shortcut blocking, and execution time measurements designed to detect sandboxed environments.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Salty 2FA Malware Victimology

Salty 2FA campaigns demonstrate a clear pattern of targeting high-value organizations across specific industries and geographic regions. The primary focus is on enterprises in the United States and European Union, with documented attacks spanning multiple sectors.

The targeting appears highly selective, focusing on organizations with valuable assets, sensitive data, or critical infrastructure access. Attackers customize their phishing lures based on the target industry, using themes such as voice messages, document access requests, payroll amendments, requests for proposals, bid invitations, and billing statements to increase credibility and response rates.

Particularly, Salty 2FA primarily targets:

  • Financial institutions and fintech platforms relying on SMS or app-based 2FA.
  • Corporate users with privileged access, such as administrators or cloud engineers.
  • Organizations using popular authentication providers (e.g., Google Authenticator, Microsoft Authenticator).
  • MSSPs and SOC teams, where compromising an analyst’s access could unlock sensitive monitoring systems.

How Salty 2FA Functions

Salty 2FA’s workflow typically includes:

Stage 1: Initial Delivery and Cloudflare Validation

A phishing link directs a victim to a compromised or attacker-controlled domain that loads a small "trampoline" JavaScript. This script initializes the Cloudflare Turnstile widget. It is a CAPTCHA-like challenge. First, it provides a veneer of legitimacy by mimicking security practices users expect from real login pages. Second, it helps filter out automated security scanners and bot detection systems.

Once the challenge is completed and a cf_response token is returned, the server delivers the HTML that initiates the main execution chain.

Stage 2: Obfuscated Entry Script

The initial page contains heavily obfuscated JavaScript with comment inserts containing "inspiring quotes" that act as noise to frustrate static analysis. The functional portion contains an obfuscated function designed to decode the address of the next stage, retrieve it, decode it using Base64 and XOR encryption, and write the result into the DOM of the current page.

Obfuscated JavaScript code Obfuscated JavaScript code

This multi-step decoding process helps evade signature-based detection systems.

Stage 3: Encrypted Payload and Fake Login Page

After loading and decoding the payload, the victim is served a large HTML page containing a convincing replica of a Microsoft 365 login interface. The page is padded with non-functional code noise, and all text strings are obfuscated rather than appearing as plain text. The login form includes proper branding elements that can be customized based on the victim's organization, including company logos, background images, and welcome text retrieved from legitimate sources or previous reconnaissance.

Forged branded login page Forged login page of a trustworthy brand

Stage 4: Client-Side Logic and Anti-Analysis All logic for switching between page states and collecting user input is handled by heavily obfuscated JavaScript. The framework uses jQuery for DOM manipulation with dynamically generated element identifiers that are encoded using Base64 and XOR encryption. Multiple defense mechanisms activate to prevent analysis, including blocking keyboard shortcuts for developer tools (F12, Ctrl+Shift+I), measuring execution time delays that indicate debugger presence, detecting when browser developer tools are open, and halting execution if analysis is suspected.

Stage 5: Credential Validation and Data Collection As the victim enters their email address, the framework immediately validates it with Microsoft's infrastructure to ensure it corresponds to a real account. This prevents attackers from wasting effort on fake or mistyped credentials. When the victim enters their password, the system again validates the credentials in real-time. If the credentials are correct and the account has MFA enabled, the system seamlessly transitions to the appropriate 2FA challenge screen.

Salty 2FA Attack Example

An analysis session of a Salty 2FA attack has been run in ANY.RUN’s Interactive Sandbox with the MITM proxy enabled.

Setting up MITM in the Sandbox Turn on MITM when setting up Sandbox analysis

This makes it possible to observe the kill chain, capture decrypted traffic, and analyze the payload step by step

Salty 2FA sample detonated in Sandbox Salty 2FA sample detonated in the Sandbox

What Salty 2FA Malware Can Do to an Endpoint Device

While Salty 2FA is predominantly a client-side phishing framework without persistent malware payloads, its impact on endpoint devices is insidious through social engineering and session hijacking. Upon clicking a phishing link, victims encounter a fake OneDrive sharing page or similar lure, leading to a credential harvester that captures usernames, passwords, and MFA responses in real-time.

Key capabilities include:

  • MFA Interception and Replay: Simulates SMS OTPs, authenticator apps, push notifications, voice calls, backup codes, and hardware tokens, allowing attackers to complete logins remotely without device compromise.
  • Dynamic Branding and Geofencing: Customizes pages to match corporate themes and blocks traffic from security vendors or cloud IPs, ensuring only human victims proceed.
  • Anti-Analysis Evasion: Disables browser dev tools, employs XOR-encrypted strings, and uses session tokens for state management, potentially leaving no local artifacts but exposing sessions to takeover.

On the endpoint, this manifests as unauthorized account access, potential lateral movement if credentials grant broader privileges, and exposure to secondary malware like ransomware. No direct file drops occur, but the stolen session can enable remote code execution via compromised admin accounts.

How Salty 2FA Threatens Businesses and Organizations

For businesses, Salty 2FA transforms routine phishing into catastrophic breaches, undermining trust in MFA and cloud ecosystems. Account takeovers grant attackers entry to sensitive data repositories, email inboxes for business email compromise (BEC), and collaboration tools for espionage or disruption.

In finance and healthcare, this risks regulatory fines under GDPR or HIPAA; in energy and government, it could lead to operational sabotage or national security leaks.

The PhaaS model amplifies threats by enabling mass-scale attacks at low cost, with dynamic infrastructure rotating domains daily to evade blocks. Organizations face escalated costs from incident response, downtime, and reputational damage.

Gathering Threat Intelligence on Salty 2FA Malware

Threat intelligence (TI) plays a critical role by:

  • Identifying emerging indicators of compromise (IOCs) linked to Salty 2FA.
  • Providing contextual data about threat actor groups deploying it.
  • Enabling proactive detection through correlation of TTPs in SIEM and EDR systems.
  • Offering real-time alerts when the malware’s infrastructure reactivates or mutates.

By integrating TI into SOC workflows, analysts can prioritize alerts and respond before attackers exploit stolen tokens.

Use ANY.RUN’s Threat Intelligence Lookup to search IOCs and behavior data linked to Salty 2FA. Start from querying the threat name to find Salty 2FA samples that ANY.RUN’s community of 500K professionals and 15K SOC teams has already analyzed. Study TTPs and gather indicators:

threatName:"salty2fa"

Salty 2FA sandbox analyses found via TI Lookup Salty 2FA sandbox analyses found via TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Salty 2FA malware exemplifies the next generation of authentication-targeting threats. As attackers shift focus from stealing passwords to intercepting identity tokens, businesses must evolve their defenses. The combination of phishing-resistant MFA, endpoint visibility, and high-quality threat intelligence is now essential to protect both infrastructure and identity.

Start gathering actionable threat intelligence on Salty 2FA by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More
Mirage2FA screenshot
Mirage2FA
mirage2fa
Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
Overlord RAT screenshot
Overlord RAT
overlord
Overlord RAT is a cross-platform remote access framework with Go-based agents and a TypeScript/Node/Bun server. It supports encrypted WebSocket C2, remote control, persistence, and multiple operating systems, including Windows, Linux, and macOS.
Read More
Interlock screenshot
Interlock
interlock
Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.
Read More
BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More