Cyber Security News

New Salty 2FA PhaaS Attacking Microsoft 365 Users to Steal Login Credentials

A sophisticated new Phishing-as-a-Service (PhaaS) framework dubbed “Salty 2FA” has emerged as a significant threat to Microsoft 365 users across the US and European industries.

This previously undocumented platform employs advanced obfuscation techniques and multi-stage execution chains specifically designed to bypass two-factor authentication mechanisms while stealing corporate credentials.

The framework targets organizations spanning finance, telecommunications, energy, logistics, and educational sectors through carefully crafted phishing campaigns based on ANY.RUN Sandbox analysis.

The malware distinguishes itself through a unique domain infrastructure pattern that combines compound domains in “.com” zones with domains registered under Russian “.ru” top-level domains.

Suspicious domain combination (Source – Any.Run)

This distinctive pairing creates a complex web of redirections and payload delivery mechanisms that have helped the platform evade traditional detection systems.

Victims receive phishing emails containing various lures, including fake voice messages, document access requests, and billing statements that redirect them to convincing Microsoft login replicas.

ANY.RUN analysts identified this previously unknown PhaaS framework during a routine phishing campaign, where they discovered multiple sandbox sessions exhibiting similar behavioral patterns despite using different domains and obfuscation techniques.

Analysis of a phishing page (Source – Any.Run)

The consistent use of Cloudflare Turnstile protection combined with the distinctive domain pairing initially flagged these campaigns as potentially related, leading to the comprehensive analysis that revealed Salty 2FA’s full capabilities.

The platform demonstrates considerable sophistication in its ability to intercept and process multiple two-factor authentication methods, including push notifications, SMS codes, voice calls, and authenticator app tokens.

This capability extends the attack beyond simple credential theft, allowing threat actors to maintain persistent access to compromised accounts even when traditional 2FA protections are in place.

Multi-Stage Execution Chain and Obfuscation Techniques

Salty 2FA’s technical architecture relies on a carefully orchestrated five-stage execution process designed to resist analysis and detection.

Obfuscated code (Source – Any.Run)

The initial stage begins with an obfuscated JavaScript function that serves as the entry point, containing inspirational quote comments as noise to complicate static analysis.

The framework employs sophisticated element ID encoding using Base64 and XOR operations with a fixed generated value, making dynamic analysis significantly more challenging.

All front-end logic relies on jQuery calls to dynamically generated element identifiers, which must be decoded through a dedicated routine before manipulation.

The platform incorporates multiple anti-analysis mechanisms, including keyboard shortcut blocking for debugging tools and execution time measurement to detect controlled environments.

Data exfiltration utilizes the same XOR technique with session-derived keys, while stolen credentials are transmitted to Russian-hosted servers through encoded POST requests containing both the encrypted data and decoding parameters.

IoC

TypeSubtypeIOC Value
Domaininnovationsteams[.]com
Domainmarketplace24ei[.]ru
Domainnexttradeitaly[.]it[.]com
Domainfrankfurtwebs[.]com[.]de
URLhxxps[://]telephony[.]nexttradeitaly[.]com/SSSuWBTmYwu/
URLhxxps[://]parochially[.]frankfurtwebs[.]com[.]de/ps6VzZb/
URLhxxps[://]marketplace24ei[.]ru//
URLhxxps[://]marketplace24ei[.]ru/790628[.]php
IP AddressEmail-extracted153[.]127[.]234[.]4
IP AddressEmail-extracted51[.]89[.]33[.]171
IP AddressEmail-extracted191[.]96[.]207[.]129
IP AddressEmail-extracted153[.]127[.]234[.]5
Emailizumi [at] yurikamome[.]com

Stop social engineering attacks before they turn into breaches: Protect your team with ANY.RUN – Start your 14-day trial 

Balaji N

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

16 seconds ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

6 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

17 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago