Possible Mamba 2FA AiTM Phishing URL Pattern

PremiumReviewedSigma · Low · v1
Category
proxy
Author
HuntRule
Published
2026-06-24
Updated
2026-08-28

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects HTTP requests matching the Mamba 2FA adversary in the middle phishing URL structure of a single letter path segment m, n or o followed by a query string carrying a Base64 encoded victim token. Mamba 2FA relays Microsoft 365 credentials and session cookies through this pattern to bypass multifactor authentication. Because the pattern is broad it should be corroborated with the known relay domains before action.

Related detections9 linkedT1557 — drag to rearrange
Suspicious mstsc Launch of RDP File From User Download or Temp Path (via process_creation)
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Malicious TCP Session Hijacking via rshijack
Suspicious Regsvr32 Squiblydoo Remote Scriptlet Execution via Command Line (via process_creation)
Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
Malicious EdgeStepper iptables DNS Redirection for Adversary-in-the-Middle
Suspicious Tycoon 2FA Credential Exfiltration Fields
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Suspicious Entra Sign-In Interrupt With High Aggregated Risk via AiTM DNS Hijacking (via azure)
Possible Mamba 2FA AiTM Phishing URL Pattern
Pivot detection · T1557 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.