216.73.217.22

Salty2FA & Tycoon2FA: Hybrid Phishing Threat

· Published 02/12/2025 21:13 · Modified 21/12/2025 18:19

Export JSON

Essential information

Published
02/12/2025 21:13
Modified
21/12/2025 18:19
Tags
2025-12-02 2fa attribution detection phishing salty2fa tycoon2fa
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 2 malware, 6 others

Description

A new hybrid threat combining elements of and has emerged, blurring the lines between distinct kits. Analysis reveals a sudden drop in activity, followed by the appearance of samples containing code from both frameworks. The hybrid shows signs of infrastructure failure, forcing a fallback to Tycoon-based hosting and payload delivery. This overlap complicates and weakens kit-specific rules. The emergence of this hybrid suggests a possible connection to Storm-1747, known operators of . Defenders are advised to update logic, expect more cross-kit overlap, and prepare for campaigns with increased flexibility and resilience to infrastructure failures.

External references