Salty2FA
Salty2FA is a phishing-as-a-service (PhaaS) framework designed to bypass MFA/2FA protections and capture user credentials and session data through multi-stage phishing flows. ANY.RUN reported Salty2FA as a sophisticated 2FA-phishing kit and observed that it used advanced tactics including cloaking via trusted platforms such as Cloudflare Turnstile. In analyzed hybrid samples, early-stage behavior attributed to Salty2FA included phishing pages hosted on Cloudflare Pages Dev, Salty2FA-like HTML/JavaScript artifacts such as motivational quotes in markup, class names following a word-plus-number pattern, and trampoline JavaScript used to retrieve and load subsequent stages into the DOM. Salty2FA-linked infrastructure included the decoded address hxxps://omvexe[.]shop//, which in one case failed DNS resolution with SERVFAIL, and the report noted a sharp decline in pure Salty2FA activity in late 2025, with many later samples appearing non-functional or no longer behaving like typical Salty2FA. ANY.RUN assessed that Salty2FA infrastructure may have suffered operational failure, leading campaigns to fall back to Tycoon2FA-based hosting and delivery. Researchers observed a hybrid Salty2FA/Tycoon2FA payload in which Salty2FA-like initial stages transitioned into later stages that mirrored Tycoon2FA nearly line-for-line, including obfuscated anti-analysis logic, Microsoft login page mimicry, dynamic routing, DGA-related infrastructure, and POSTs to characteristic domains. The overlap was assessed as consistent with earlier hypotheses of a possible connection to Storm-1747, identified in the content as known operators of Tycoon2FA. Reported indicators associated with the hybrid activity include 1otyu7944x8[.]workers[.]dev, xm65lwf0pr2e[.]workers[.]dev, and lapointelegal-portail[.]pages[.]dev.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated Phishing-as-a-Service framework, Salty2FA is used to facilitate phishing attacks, likely targeting two-factor authentication.
Salty2FA is a phishing-as-a-service kit designed to bypass multi-factor authentication (MFA) by capturing user credentials and session data through multi-stage, deceptive logic flows. It uses advanced tactics such as code obfuscation, 'trampoline' JavaScript, and domain patterning, and has been observed cloaking within trusted platforms to evade detection.
A phishing-as-a-service (PhaaS) / 2FA phishing kit used to deliver multi-stage, client-side JavaScript payloads that render fake Microsoft authentication pages, perform anti-analysis/anti-debug checks, and exfiltrate stolen authentication data. In late 2025, Salty2FA campaigns were observed failing over to Tycoon2FA infrastructure/payload stages due to apparent Salty infrastructure/DNS issues.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.