Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

Whisper 2FA

Also known asWhisper 2FA

Whisper 2FA is a phishing kit / phishing-as-a-service offering identified by Barracuda as an aggressive newer entrant in the 2025 PhaaS ecosystem and as one of the kits benefiting from the disruption of Tycoon 2FA. It is described as a lightweight kit built for fast deployment and MFA bypass, using AJAX-based exfiltration rather than complex reverse proxies. Reported MFA bypass support includes push notifications, SMS, voice calls, and app-based codes. Barracuda also noted strong anti-analysis obfuscation. The content places Whisper 2FA alongside other phishing kits such as Tycoon 2FA, Mamba 2FA, EvilProxy, Sneaky 2FA, Cephas, and GhostFrame, but does not attribute it to a specific nation state or operator. Known alias in the provided content: whisper_2fa.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.