Phishing 2.0 nutzt Subdomain-Rotation und Geoblocking. janews – Shutterstock.com Eine kürzlich aufgedeckte Phishing-Kampagne steht in Verbindung mit Salty2FA, einem Phishing-as-a-Service-(PhaaS-)Framework. Es soll entwickelt worden sein, um Multi-Faktor-Authentifizierung (MFA) zu umgehen. Wie die Cybersicherheitsfirma Ontinue herausgefunden hat, fängt sie Verifizierungsmethoden ab, rotiert Subdomains und tarnt sich innerhalb vertrauenswürdiger Plattformen wie Cloudflare Turnstile. In unserer US-Schwesterpublikation CSO…
Category: Multifactor Authentication, Phishing, Security
Exploits, Global Security News, Multifactor Authentication, Phishing, Security
Phishing kit Salty2FA washes away confidence in MFA
A newly uncovered phishing campaign has been linked to Salty2FA, a phishing-as-a-service framework built to sidestep multi-factor authentication (MFA). The ongoing campaign is using the kit to bypass MFA protections by intercepting verification methods, rotating subdomains, and cloaking themselves within trusted platforms like Cloudflare Turnstile, according to cybersecurity firm Ontinue’s findings. In a disclosure shared…
