Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Salty 2FA

58
Global rank
68 infographic chevron month
Month rank
82 infographic chevron week
Week rank
0
IOCs

Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.

Phishingkit
Type
Unknown
Origin
1 June, 2025
First seen
26 August, 2026
Last seen

How to analyze Salty 2FA with ANY.RUN

Type
Unknown
Origin
1 June, 2025
First seen
26 August, 2026
Last seen

IOCs

IP addresses
13.107.246.44
150.171.28.11
213.128.68.170
48.209.138.168
150.171.27.11
188.114.97.3
74.125.250.129
104.19.230.21
2.19.122.66
104.17.112.233
162.159.207.0
104.18.13.205
104.18.94.41
150.171.22.17
104.18.95.41
142.251.110.139
48.209.133.15
104.18.12.205
23.43.32.148
104.19.229.21
Hashes
fac0a85e4f5907c8036b0052214b777ddbacea9420e5903526272dc76bd4c7b6
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
14895bf43ce9b76c0ff4f9aef93dbe8bb6ca496894870cf0c007b189e0cef00e
7ccc7b17bfe01c3c7dd33eff8f80d0b57fc9b175815e766c9c1c1e893725e20f
6c69ce0fe6fab14f1990a320d704fee362c175c00eb6c9224aa6f41108918ca6
5f4229d18e5606330146ee13bdf726e10c1e06cbb15368c47f1ae68abe9ce4ba
ec78ddd4ccf32b5d76ec701a20167c3fbd146d79a505e4fb0421fc1e5cf4aa63
41ce6a7b18364efecced0419b42165d4f86c43643bbe1043014d4142cf86186a
57f81a5fcbd1fefd6ec3cdd525a85b707b4eead532c1b3092daafd88ee9268ec
89082fb05229826bc222f5d22c158235f025f0e6df67ff135a18bd899e13bb8f
Domains
aadcdn.msftauth.net
959recombine.crestcore.it.com
tinyurl.com
activation-v2.sls.microsoft.com
ywnjb.employee-service.net
clients2.googleusercontent.com
stun1.l.google.com
notification.employee-service.net
challenges.cloudflare.com
aadcdn.msauth.net
stun.l.google.com
kalipdunyasi.com.tr
edge.microsoft.com
www.bing.com
config.edge.skype.com
newassets.hcaptcha.com
update.googleapis.com
api.hcaptcha.com
js.hcaptcha.com
stun.cloudflare.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:tgu9ofrncjv3b8eip7jq0bkl6y5kgqbompubzs9udfo&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://kalipdunyasi.com.tr/?num=1-1&link=https://959recombine.crestcore.it.com/mattress546/
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://959recombine.crestcore.it.com/mattress546/
https://959recombine.crestcore.it.com/mattress546/module.3944f8983090969f0038.js
https://959recombine.crestcore.it.com/mattress546/favicon.png
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d250%2526e%253d1
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://update.googleapis.com/service/update2/json?cup2key=14:zfip84lntjhm72oyze4nwpj9dvmkqeambecmfcmwf-y&cup2hreq=8499b64968af99e64550b18df352de520680c646666676170fc9adb8242bee90
https://clients2.googleusercontent.com/crx/blobs/abe5cl6a_jaanxapcjclooga79zaaqm3tadaaxpzgbj_5tef2gcwgawlwvojctwjy-62xnz5nkplhywefhkfca7ve1mtom8zrfv598knndu2neqdltxpxs0ljjjkmozedq0axlka5z-i_mcpvgwijs_fx-_dkkqdwg3y/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_109_1_0.crx
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://tinyurl.com/cpa8tmr7
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2536
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7351
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10494
comments 0

Salty 2FA Malware: When Hackers Turn Authentication Against You

Key Takeaways

  1. MFA Alone Is Not Sufficient Protection. Salty 2FA can bypass six different types of multi-factor authentication including SMS codes, push notifications, voice calls, and authenticator app OTPs. Organizations must transition to phishing-resistant authentication methods like FIDO2/WebAuthn hardware security keys that cannot be intercepted through man-in-the-middle attacks.

  2. Behavioral Detection Outperforms Static Signatures. Indicators like domains and IP addresses change constantly as Salty 2FA rotates infrastructure, making signature-based detection unreliable. The most effective detection focuses on behavioral patterns that remain consistent: the unique .com + .ru domain combinations, multi-stage execution chains, Cloudflare service usage patterns, and encoded data exfiltration methods.

  3. Targeted Industries Face Elevated Risk. Salty 2FA demonstrates clear targeting preferences for high-value sectors including financial services, energy infrastructure, logistics, telecommunications, government, and consulting firms.

  4. Multi-Layered Defense Is Essential. No single security control can prevent Salty 2FA attacks. Effective defense requires multiple overlapping layers: advanced email security with link sandboxing, DNS filtering with pattern-based detection, phishing-resistant authentication, endpoint detection and response, user behavior analytics, security awareness training, and threat intelligence integration.

  5. Threat Intelligence Enables Proactive Defense. Early warning about the framework's emergence, understanding of its behavioral patterns, context about targeting and techniques, and continuous IOC feeds enable organizations to implement protections before becoming victims. Leverage Threat Intelligence Lookup to explore fresh contextual threat data.

  6. User Awareness Remains Critical. Trained users who can recognize phishing attempts, verify URLs before entering credentials, report suspicious emails, and understand the importance of not approving unexpected MFA requests provide essential human intelligence and early warning.

Enable users to check suspicious messages and attachments in ANY.RUN’s Interactive Sandbox:

PDF document detected as phishing and Salty 2FA by ANY.RUN PDF document recognized as phishing and Salty 2FA by ANY.RUN

  1. Interactive Sandbox Analysis Is Necessary for Detection. Traditional static analysis fails against Salty 2FA's extensive obfuscation, anti-analysis mechanisms, and multi-stage execution. Interactive sandbox environments that simulate user interactions and capture real-time behavior are essential for understanding how the framework operates, extracting IOCs, mapping infrastructure, and developing effective detection rules.

What is Salty 2FA Malware?

Salty 2FA represents the evolution of phishing kits, blending enterprise-grade sophistication with the accessibility of a service model. Discovered by ANY.RUN’s analysts in mid-2025, the framework draws inspiration from groups like Storm-1575 (known for the Dadsec platform) and Storm-1747 (behind Tycoon 2FA) but stands distinct in its infrastructure and techniques.

The name "Salty 2FA" derives from its "salted" payloads — heavily obfuscated code that distinguishes it from other phishing kits during analysis.

Unlike traditional credential stealers that focus on static passwords, Salty 2FA specifically targets time-based one-time passwords (TOTPs) and push-based 2FA systems. It intercepts or manipulates the authentication process, allowing adversaries to impersonate legitimate users in real time.

Salty 2FA is often deployed in multi-stage attacks, where it follows initial compromise through phishing, malicious attachments, or fake authentication apps. Once inside, it hooks into browser sessions or mobile apps to intercept verification tokens and authentication prompts.

The malware’s modular architecture enables it to adapt to different environments from individual endpoints to enterprise networks, making it a versatile and persistent threat.

The framework can validate stolen credentials in real-time, intercept multiple types of two-factor authentication methods, and maintain persistent communication with command-and-control servers through an encoded data exfiltration system.

The entire operation is protected by multiple layers of anti-analysis mechanisms, including JavaScript-based anti-debugging features, keyboard shortcut blocking, and execution time measurements designed to detect sandboxed environments.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Salty 2FA Malware Victimology

Salty 2FA campaigns demonstrate a clear pattern of targeting high-value organizations across specific industries and geographic regions. The primary focus is on enterprises in the United States and European Union, with documented attacks spanning multiple sectors.

The targeting appears highly selective, focusing on organizations with valuable assets, sensitive data, or critical infrastructure access. Attackers customize their phishing lures based on the target industry, using themes such as voice messages, document access requests, payroll amendments, requests for proposals, bid invitations, and billing statements to increase credibility and response rates.

Particularly, Salty 2FA primarily targets:

  • Financial institutions and fintech platforms relying on SMS or app-based 2FA.
  • Corporate users with privileged access, such as administrators or cloud engineers.
  • Organizations using popular authentication providers (e.g., Google Authenticator, Microsoft Authenticator).
  • MSSPs and SOC teams, where compromising an analyst’s access could unlock sensitive monitoring systems.

How Salty 2FA Functions

Salty 2FA’s workflow typically includes:

Stage 1: Initial Delivery and Cloudflare Validation

A phishing link directs a victim to a compromised or attacker-controlled domain that loads a small "trampoline" JavaScript. This script initializes the Cloudflare Turnstile widget. It is a CAPTCHA-like challenge. First, it provides a veneer of legitimacy by mimicking security practices users expect from real login pages. Second, it helps filter out automated security scanners and bot detection systems.

Once the challenge is completed and a cf_response token is returned, the server delivers the HTML that initiates the main execution chain.

Stage 2: Obfuscated Entry Script

The initial page contains heavily obfuscated JavaScript with comment inserts containing "inspiring quotes" that act as noise to frustrate static analysis. The functional portion contains an obfuscated function designed to decode the address of the next stage, retrieve it, decode it using Base64 and XOR encryption, and write the result into the DOM of the current page.

Obfuscated JavaScript code Obfuscated JavaScript code

This multi-step decoding process helps evade signature-based detection systems.

Stage 3: Encrypted Payload and Fake Login Page

After loading and decoding the payload, the victim is served a large HTML page containing a convincing replica of a Microsoft 365 login interface. The page is padded with non-functional code noise, and all text strings are obfuscated rather than appearing as plain text. The login form includes proper branding elements that can be customized based on the victim's organization, including company logos, background images, and welcome text retrieved from legitimate sources or previous reconnaissance.

Forged branded login page Forged login page of a trustworthy brand

Stage 4: Client-Side Logic and Anti-Analysis All logic for switching between page states and collecting user input is handled by heavily obfuscated JavaScript. The framework uses jQuery for DOM manipulation with dynamically generated element identifiers that are encoded using Base64 and XOR encryption. Multiple defense mechanisms activate to prevent analysis, including blocking keyboard shortcuts for developer tools (F12, Ctrl+Shift+I), measuring execution time delays that indicate debugger presence, detecting when browser developer tools are open, and halting execution if analysis is suspected.

Stage 5: Credential Validation and Data Collection As the victim enters their email address, the framework immediately validates it with Microsoft's infrastructure to ensure it corresponds to a real account. This prevents attackers from wasting effort on fake or mistyped credentials. When the victim enters their password, the system again validates the credentials in real-time. If the credentials are correct and the account has MFA enabled, the system seamlessly transitions to the appropriate 2FA challenge screen.

Salty 2FA Attack Example

An analysis session of a Salty 2FA attack has been run in ANY.RUN’s Interactive Sandbox with the MITM proxy enabled.

Setting up MITM in the Sandbox Turn on MITM when setting up Sandbox analysis

This makes it possible to observe the kill chain, capture decrypted traffic, and analyze the payload step by step

Salty 2FA sample detonated in Sandbox Salty 2FA sample detonated in the Sandbox

What Salty 2FA Malware Can Do to an Endpoint Device

While Salty 2FA is predominantly a client-side phishing framework without persistent malware payloads, its impact on endpoint devices is insidious through social engineering and session hijacking. Upon clicking a phishing link, victims encounter a fake OneDrive sharing page or similar lure, leading to a credential harvester that captures usernames, passwords, and MFA responses in real-time.

Key capabilities include:

  • MFA Interception and Replay: Simulates SMS OTPs, authenticator apps, push notifications, voice calls, backup codes, and hardware tokens, allowing attackers to complete logins remotely without device compromise.
  • Dynamic Branding and Geofencing: Customizes pages to match corporate themes and blocks traffic from security vendors or cloud IPs, ensuring only human victims proceed.
  • Anti-Analysis Evasion: Disables browser dev tools, employs XOR-encrypted strings, and uses session tokens for state management, potentially leaving no local artifacts but exposing sessions to takeover.

On the endpoint, this manifests as unauthorized account access, potential lateral movement if credentials grant broader privileges, and exposure to secondary malware like ransomware. No direct file drops occur, but the stolen session can enable remote code execution via compromised admin accounts.

How Salty 2FA Threatens Businesses and Organizations

For businesses, Salty 2FA transforms routine phishing into catastrophic breaches, undermining trust in MFA and cloud ecosystems. Account takeovers grant attackers entry to sensitive data repositories, email inboxes for business email compromise (BEC), and collaboration tools for espionage or disruption.

In finance and healthcare, this risks regulatory fines under GDPR or HIPAA; in energy and government, it could lead to operational sabotage or national security leaks.

The PhaaS model amplifies threats by enabling mass-scale attacks at low cost, with dynamic infrastructure rotating domains daily to evade blocks. Organizations face escalated costs from incident response, downtime, and reputational damage.

Gathering Threat Intelligence on Salty 2FA Malware

Threat intelligence (TI) plays a critical role by:

  • Identifying emerging indicators of compromise (IOCs) linked to Salty 2FA.
  • Providing contextual data about threat actor groups deploying it.
  • Enabling proactive detection through correlation of TTPs in SIEM and EDR systems.
  • Offering real-time alerts when the malware’s infrastructure reactivates or mutates.

By integrating TI into SOC workflows, analysts can prioritize alerts and respond before attackers exploit stolen tokens.

Use ANY.RUN’s Threat Intelligence Lookup to search IOCs and behavior data linked to Salty 2FA. Start from querying the threat name to find Salty 2FA samples that ANY.RUN’s community of 500K professionals and 15K SOC teams has already analyzed. Study TTPs and gather indicators:

threatName:"salty2fa"

Salty 2FA sandbox analyses found via TI Lookup Salty 2FA sandbox analyses found via TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Salty 2FA malware exemplifies the next generation of authentication-targeting threats. As attackers shift focus from stealing passwords to intercepting identity tokens, businesses must evolve their defenses. The combination of phishing-resistant MFA, endpoint visibility, and high-quality threat intelligence is now essential to protect both infrastructure and identity.

Start gathering actionable threat intelligence on Salty 2FA by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

FlowerStorm screenshot
FlowerStorm
flowerstorm
FlowerStorm is a phishing-as-a-service (PhaaS) platform used by cybercriminals to steal Microsoft 365 credentials and bypass multi-factor authentication (MFA) protections through adversary-in-the-middle (AiTM) attacks. Emerging after the disruption of Rockstar2FA in late 2024, FlowerStorm rapidly gained popularity among attackers targeting enterprises across North America and Europe.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More
Cerber screenshot
Cerber
cerber
Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.
Read More
DonutLoader screenshot
DonutLoader
donutloader donut
DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More