Salty 2FA is a phishing-as-a-service (PhaaS) phishing framework focused on stealing Microsoft 365 credentials. Open-source reporting cited in the provided content states that it has been attributed to the threat actor Storm-1575. The framework has been reported targeting organizations across the US and Europe, with victims or intended targets in finance, telecom, energy, logistics, healthcare, consulting, education, and government sectors. The content specifically describes it as hitting Microsoft 365 users and as a widespread phishing kit observed in August 2025. No specific technical indicators of compromise, delivery artifacts, or infrastructure details are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Salty 2FA is a phishing-as-a-service platform designed to steal Microsoft 365 credentials, including bypassing two-factor authentication mechanisms.
Phishing kit/framework designed to bypass two-factor authentication, targeting Microsoft 365 users across multiple industries and regions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.