This advisory document provides situational awareness regarding a new Phishing-as-a-Service tool known as Mamba 2FA. The document outlines how Mamba 2FA can bypass email firewalls and multifactor authentication (MFA) by exploiting adversary-in-the-middle (AiTM) methods. It explains that the platform allows cybercriminals to conduct phishing attacks without needing to defeat authentication directly, thus rendering traditional protective measures ineffective. The advisory details the operational aspects of Mamba 2FA, including its ability to capture session tokens by recreating legitimate login pages, which poses significant risks to user accounts. Additionally, it presents recommendations for organizations to mitigate risks associated with phishing attacks, such as training users to identify phishing attempts, implementing Zero Trust architecture, and developing incident playbooks for compromised accounts. The document aims to inform and prepare organizations against the evolving threat landscape posed by sophisticated phishing techniques.