Threats Tagged '2fa'
View all threats tagged with '2fa'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged '2fa'
Click on any threat for detailed analysis and mitigation recommendations
A hybrid phishing threat combining Salty2FA and Tycoon2FA phishing kits has emerged, leveraging code and infrastructure from both frameworks. This hybridization appears driven by Salty2FA infrastructure failures, causing fallback to Tycoon2FA hosting and payload delivery. The overlap complicates attribution and weakens detection rules tailored to either kit alone. The threat is linked to the Storm-1747 adversary group, known for Tycoon2FA operations. Indicators include multiple suspicious domains used for hosting phishing pages. Defenders should update detection logic to address cross-kit overlaps and prepare for more resilient phishing campaigns that can adapt to infrastructure disruptions. The threat is rated medium severity and does not require exploits in the wild or CVSS scoring. European organizations should be vigilant due to the widespread use of 2FA and phishing susceptibility. Mitigation requires tailored detection updates, domain monitoring, and user awareness enhancements. Join the discussion | AlienVault OTX General | 12/02/2025, 21:13:43 UTC Added: 12/03/2025, 11:15:39 UTC |
Showing 1 to 1 of 1 result