Geek Guy

Category: Multifactor Authentication, Phishing, Security

Neues Phishing-Framework umgeht Multi-Faktor-Authentifizierung

Phishing 2.0 nutzt Subdomain-Rotation und Geoblocking. janews – Shutterstock.com Eine kürzlich aufgedeckte Phishing-Kampagne steht in Verbindung mit Salty2FA, einem Phishing-as-a-Service-(PhaaS-)Framework. Es soll entwickelt worden sein, um Multi-Faktor-Authentifizierung (MFA) zu umgehen. Wie die Cybersicherheitsfirma Ontinue herausgefunden hat, fängt sie Verifizierungsmethoden ab, rotiert Subdomains und tarnt sich innerhalb vertrauenswürdiger Plattformen wie Cloudflare Turnstile. In unserer US-Schwesterpublikation CSO…

Phishing kit Salty2FA washes away confidence in MFA

A newly uncovered phishing campaign has been linked to Salty2FA, a phishing-as-a-service framework built to sidestep multi-factor authentication (MFA). The ongoing campaign is using the kit to bypass MFA protections by intercepting verification methods, rotating subdomains, and cloaking themselves within trusted platforms like Cloudflare Turnstile, according to cybersecurity firm Ontinue’s findings. In a disclosure shared…