Mamba 2FA is an adversary-in-the-middle (AiTM) phishing-as-a-service framework targeting cloud authentication, particularly Microsoft 365. It began appearing in phishing operations around 2023 and remained widely used in 2025. It provides cybercriminal operators with realistic authentication-page emulation, automated session handling, and real-time backend communication to facilitate credential theft and bypass conventional multifactor authentication.
Its phishing interfaces imitate Microsoft sign-in pages and incorporate organization-specific branding. An observed workflow presents an authentication loading screen followed by a password-only prompt, creating the impression that the victim’s identity has already been established. Client-side JavaScript captures password input and prepares it for transmission. After submission, the browser redirects to a legitimate website to reduce suspicion.
Mamba-associated campaigns use email lures impersonating Microsoft security alerts, document notifications, and account-activity warnings. Distribution includes embedded phishing links, branded HTML emails, and attached email messages. Encoded link parameters, short-lived phishing addresses, and redirect chains help conceal operational details and reduce detection by reputation-based filtering. Its primary focus is enterprise cloud identity rather than a specific endpoint operating system.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Security experts have issued a warning about the continued risk of Tycoon 2FA attacks... Before the takedown, Tycoon 2FA was behind tens of millions of phishing messages, reaching over 500,000 organizations each month worldwide.
The password field is monitored by client-side JavaScript. Input handling occurs within the browser, preparing the entered credentials for transmission immediately upon submission.
MITRE FRAMEWORK Tactic Technique ID Technique Name ... Credential Access T1110.004 Brute Force: Credential Stuffing
Collectively, these trends reinforce the ongoing threat posed by AiTM phishing kits to enterprise cloud environments and underscore the need for continuous monitoring and adaptive defensive controls.
The password field is monitored by client-side JavaScript. Input handling occurs within the browser, preparing the entered credentials for transmission immediately upon submission.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An established phishing kit/platform mentioned as increasing campaign activity after the Tycoon 2FA takedown.
A phishing-as-a-service framework designed to facilitate credential theft, session interception, and MFA bypass against cloud identity services, particularly Microsoft 365. The observed flow uses encoded URL parameters, pre-established identity context, organization-branded Microsoft-style password prompts, client-side JavaScript credential capture, and redirection to legitimate websites after submission. Campaigns commonly use email lures and sometimes redirect chains or short-lived URLs. The report assesses session-aware AiTM capabilities, while its described observations primarily demonstrate password capture and authentication-page impersonation.
A phishing-as-a-service kit used in high-volume phishing campaigns, noted for supporting multifactor authentication (MFA) bypass techniques and enabling more sophisticated, harder-to-detect credential theft workflows.
A phishing kit focused on bypassing multi-factor authentication (MFA), used in phishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.