Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Salty 2FA

68
Global rank
92 infographic chevron month
Month rank
184 infographic chevron week
Week rank

Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.

Phishingkit
Type
Unknown
Origin
1 June, 2025
First seen
2 September, 2026
Last seen

How to analyze Salty 2FA with ANY.RUN

Type
Unknown
Origin
1 June, 2025
First seen
2 September, 2026
Last seen

IOCs

IP addresses
142.251.13.94
188.114.97.3
150.171.109.105
104.102.45.216
20.190.160.65
52.123.224.69
142.250.154.95
2.19.122.64
48.209.133.15
74.178.76.54
142.251.127.84
74.179.77.204
142.251.152.119
95.101.78.11
150.171.28.11
172.211.123.249
142.251.110.132
142.251.20.100
48.192.1.64
104.18.22.222
Hashes
db39694c444ea393569aafb2cd8ec865006f3df9ecbcb7996e7b219b30ec366d
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
3dbd2c90050b652d63656481c3e5871c52261575292db77d4ea63419f187a55b
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
35872a3343d4b4768fe4702a8dc18b749933e81210db13466ad172bd2880f6eb
de6d7b7c2427ec4e738407d7834b71941f69166b030355e00f325ff1391df5a1
Domains
www.microsoft.com
edge.microsoft.com
config.edge.skype.com
play.google.com
slscr.update.microsoft.com
fonts.googleapis.com
go.microsoft.com
settings-win.data.microsoft.com
edge-consumer-static.azureedge.net
accounts.google.com
a.nel.cloudflare.com
static.edge.microsoftapp.net
fonts.gstatic.com
documentreview01.echomintes.digital
mail.google.com
stun.l.google.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
www.gstatic.com
activation-v2.sls.microsoft.com
update.googleapis.com
URLs
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:yuj3po6gwzihzf1i84rdx3r21nluwloqtfr2guzm05s&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://documentreview01.echomintes.digital/492iprotected/
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://documentreview01.echomintes.digital/492iprotected/client.2b84147935fcfa4e3b76.js
https://documentreview01.echomintes.digital/favicon.ico
https://fonts.googleapis.com/css2?family=montserrat:wght@300;400;500;600;700;800;900&display=swap
https://www.bing.com/dsb/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=us&setlang=en-us&clientdatetime=9%2f2%2f2026%2c%2011%3a40%3a50%20am
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://login.live.com/rst2.srf
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1788363649&lafgdate=0
https://login.live.com/ppsecure/deviceaddcredential.srf
https://www.bing.com/th?id=odswg.51129e50-5265-4d00-a162-fd80a3ed440f&pid=dsb
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 329
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 579
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 2170
comments 0

Salty 2FA Malware: When Hackers Turn Authentication Against You

Key Takeaways

  1. MFA Alone Is Not Sufficient Protection. Salty 2FA can bypass six different types of multi-factor authentication including SMS codes, push notifications, voice calls, and authenticator app OTPs. Organizations must transition to phishing-resistant authentication methods like FIDO2/WebAuthn hardware security keys that cannot be intercepted through man-in-the-middle attacks.

  2. Behavioral Detection Outperforms Static Signatures. Indicators like domains and IP addresses change constantly as Salty 2FA rotates infrastructure, making signature-based detection unreliable. The most effective detection focuses on behavioral patterns that remain consistent: the unique .com + .ru domain combinations, multi-stage execution chains, Cloudflare service usage patterns, and encoded data exfiltration methods.

  3. Targeted Industries Face Elevated Risk. Salty 2FA demonstrates clear targeting preferences for high-value sectors including financial services, energy infrastructure, logistics, telecommunications, government, and consulting firms.

  4. Multi-Layered Defense Is Essential. No single security control can prevent Salty 2FA attacks. Effective defense requires multiple overlapping layers: advanced email security with link sandboxing, DNS filtering with pattern-based detection, phishing-resistant authentication, endpoint detection and response, user behavior analytics, security awareness training, and threat intelligence integration.

  5. Threat Intelligence Enables Proactive Defense. Early warning about the framework's emergence, understanding of its behavioral patterns, context about targeting and techniques, and continuous IOC feeds enable organizations to implement protections before becoming victims. Leverage Threat Intelligence Lookup to explore fresh contextual threat data.

  6. User Awareness Remains Critical. Trained users who can recognize phishing attempts, verify URLs before entering credentials, report suspicious emails, and understand the importance of not approving unexpected MFA requests provide essential human intelligence and early warning.

Enable users to check suspicious messages and attachments in ANY.RUN’s Interactive Sandbox:

PDF document detected as phishing and Salty 2FA by ANY.RUN PDF document recognized as phishing and Salty 2FA by ANY.RUN

  1. Interactive Sandbox Analysis Is Necessary for Detection. Traditional static analysis fails against Salty 2FA's extensive obfuscation, anti-analysis mechanisms, and multi-stage execution. Interactive sandbox environments that simulate user interactions and capture real-time behavior are essential for understanding how the framework operates, extracting IOCs, mapping infrastructure, and developing effective detection rules.

What is Salty 2FA Malware?

Salty 2FA represents the evolution of phishing kits, blending enterprise-grade sophistication with the accessibility of a service model. Discovered by ANY.RUN’s analysts in mid-2025, the framework draws inspiration from groups like Storm-1575 (known for the Dadsec platform) and Storm-1747 (behind Tycoon 2FA) but stands distinct in its infrastructure and techniques.

The name "Salty 2FA" derives from its "salted" payloads — heavily obfuscated code that distinguishes it from other phishing kits during analysis.

Unlike traditional credential stealers that focus on static passwords, Salty 2FA specifically targets time-based one-time passwords (TOTPs) and push-based 2FA systems. It intercepts or manipulates the authentication process, allowing adversaries to impersonate legitimate users in real time.

Salty 2FA is often deployed in multi-stage attacks, where it follows initial compromise through phishing, malicious attachments, or fake authentication apps. Once inside, it hooks into browser sessions or mobile apps to intercept verification tokens and authentication prompts.

The malware’s modular architecture enables it to adapt to different environments from individual endpoints to enterprise networks, making it a versatile and persistent threat.

The framework can validate stolen credentials in real-time, intercept multiple types of two-factor authentication methods, and maintain persistent communication with command-and-control servers through an encoded data exfiltration system.

The entire operation is protected by multiple layers of anti-analysis mechanisms, including JavaScript-based anti-debugging features, keyboard shortcut blocking, and execution time measurements designed to detect sandboxed environments.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Salty 2FA Malware Victimology

Salty 2FA campaigns demonstrate a clear pattern of targeting high-value organizations across specific industries and geographic regions. The primary focus is on enterprises in the United States and European Union, with documented attacks spanning multiple sectors.

The targeting appears highly selective, focusing on organizations with valuable assets, sensitive data, or critical infrastructure access. Attackers customize their phishing lures based on the target industry, using themes such as voice messages, document access requests, payroll amendments, requests for proposals, bid invitations, and billing statements to increase credibility and response rates.

Particularly, Salty 2FA primarily targets:

  • Financial institutions and fintech platforms relying on SMS or app-based 2FA.
  • Corporate users with privileged access, such as administrators or cloud engineers.
  • Organizations using popular authentication providers (e.g., Google Authenticator, Microsoft Authenticator).
  • MSSPs and SOC teams, where compromising an analyst’s access could unlock sensitive monitoring systems.

How Salty 2FA Functions

Salty 2FA’s workflow typically includes:

Stage 1: Initial Delivery and Cloudflare Validation

A phishing link directs a victim to a compromised or attacker-controlled domain that loads a small "trampoline" JavaScript. This script initializes the Cloudflare Turnstile widget. It is a CAPTCHA-like challenge. First, it provides a veneer of legitimacy by mimicking security practices users expect from real login pages. Second, it helps filter out automated security scanners and bot detection systems.

Once the challenge is completed and a cf_response token is returned, the server delivers the HTML that initiates the main execution chain.

Stage 2: Obfuscated Entry Script

The initial page contains heavily obfuscated JavaScript with comment inserts containing "inspiring quotes" that act as noise to frustrate static analysis. The functional portion contains an obfuscated function designed to decode the address of the next stage, retrieve it, decode it using Base64 and XOR encryption, and write the result into the DOM of the current page.

Obfuscated JavaScript code Obfuscated JavaScript code

This multi-step decoding process helps evade signature-based detection systems.

Stage 3: Encrypted Payload and Fake Login Page

After loading and decoding the payload, the victim is served a large HTML page containing a convincing replica of a Microsoft 365 login interface. The page is padded with non-functional code noise, and all text strings are obfuscated rather than appearing as plain text. The login form includes proper branding elements that can be customized based on the victim's organization, including company logos, background images, and welcome text retrieved from legitimate sources or previous reconnaissance.

Forged branded login page Forged login page of a trustworthy brand

Stage 4: Client-Side Logic and Anti-Analysis All logic for switching between page states and collecting user input is handled by heavily obfuscated JavaScript. The framework uses jQuery for DOM manipulation with dynamically generated element identifiers that are encoded using Base64 and XOR encryption. Multiple defense mechanisms activate to prevent analysis, including blocking keyboard shortcuts for developer tools (F12, Ctrl+Shift+I), measuring execution time delays that indicate debugger presence, detecting when browser developer tools are open, and halting execution if analysis is suspected.

Stage 5: Credential Validation and Data Collection As the victim enters their email address, the framework immediately validates it with Microsoft's infrastructure to ensure it corresponds to a real account. This prevents attackers from wasting effort on fake or mistyped credentials. When the victim enters their password, the system again validates the credentials in real-time. If the credentials are correct and the account has MFA enabled, the system seamlessly transitions to the appropriate 2FA challenge screen.

Salty 2FA Attack Example

An analysis session of a Salty 2FA attack has been run in ANY.RUN’s Interactive Sandbox with the MITM proxy enabled.

Setting up MITM in the Sandbox Turn on MITM when setting up Sandbox analysis

This makes it possible to observe the kill chain, capture decrypted traffic, and analyze the payload step by step

Salty 2FA sample detonated in Sandbox Salty 2FA sample detonated in the Sandbox

What Salty 2FA Malware Can Do to an Endpoint Device

While Salty 2FA is predominantly a client-side phishing framework without persistent malware payloads, its impact on endpoint devices is insidious through social engineering and session hijacking. Upon clicking a phishing link, victims encounter a fake OneDrive sharing page or similar lure, leading to a credential harvester that captures usernames, passwords, and MFA responses in real-time.

Key capabilities include:

  • MFA Interception and Replay: Simulates SMS OTPs, authenticator apps, push notifications, voice calls, backup codes, and hardware tokens, allowing attackers to complete logins remotely without device compromise.
  • Dynamic Branding and Geofencing: Customizes pages to match corporate themes and blocks traffic from security vendors or cloud IPs, ensuring only human victims proceed.
  • Anti-Analysis Evasion: Disables browser dev tools, employs XOR-encrypted strings, and uses session tokens for state management, potentially leaving no local artifacts but exposing sessions to takeover.

On the endpoint, this manifests as unauthorized account access, potential lateral movement if credentials grant broader privileges, and exposure to secondary malware like ransomware. No direct file drops occur, but the stolen session can enable remote code execution via compromised admin accounts.

How Salty 2FA Threatens Businesses and Organizations

For businesses, Salty 2FA transforms routine phishing into catastrophic breaches, undermining trust in MFA and cloud ecosystems. Account takeovers grant attackers entry to sensitive data repositories, email inboxes for business email compromise (BEC), and collaboration tools for espionage or disruption.

In finance and healthcare, this risks regulatory fines under GDPR or HIPAA; in energy and government, it could lead to operational sabotage or national security leaks.

The PhaaS model amplifies threats by enabling mass-scale attacks at low cost, with dynamic infrastructure rotating domains daily to evade blocks. Organizations face escalated costs from incident response, downtime, and reputational damage.

Gathering Threat Intelligence on Salty 2FA Malware

Threat intelligence (TI) plays a critical role by:

  • Identifying emerging indicators of compromise (IOCs) linked to Salty 2FA.
  • Providing contextual data about threat actor groups deploying it.
  • Enabling proactive detection through correlation of TTPs in SIEM and EDR systems.
  • Offering real-time alerts when the malware’s infrastructure reactivates or mutates.

By integrating TI into SOC workflows, analysts can prioritize alerts and respond before attackers exploit stolen tokens.

Use ANY.RUN’s Threat Intelligence Lookup to search IOCs and behavior data linked to Salty 2FA. Start from querying the threat name to find Salty 2FA samples that ANY.RUN’s community of 500K professionals and 15K SOC teams has already analyzed. Study TTPs and gather indicators:

threatName:"salty2fa"

Salty 2FA sandbox analyses found via TI Lookup Salty 2FA sandbox analyses found via TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Salty 2FA malware exemplifies the next generation of authentication-targeting threats. As attackers shift focus from stealing passwords to intercepting identity tokens, businesses must evolve their defenses. The combination of phishing-resistant MFA, endpoint visibility, and high-quality threat intelligence is now essential to protect both infrastructure and identity.

Start gathering actionable threat intelligence on Salty 2FA by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

Phorpiex screenshot
Phorpiex
phorpiex
Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.
Read More
Remcos screenshot
Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.
Read More
ClickLock screenshot
ClickLock
clicklock
ClickLock is a macOS information stealer and remote backdoor distributed via deceptive, terminal-based social engineering pages. Once executed, it bypasses Gatekeeper checks by stripping download quarantine flags and signing its executable with ad-hoc digital certificates. If users resist its initial demands, the malware initiates high-frequency background loops that repeatedly kill vital operating system applications to force plaintext password entry. It exfiltrates captured browser data, system keychain credentials, and cryptocurrency wallets to a Telegram bot before establishing a permanent backdoor.
Read More
Kali365 screenshot
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More