: The term "pomor" likely refers to the username on the infected machine or a specific campaign tag used by the attacker.
: Use app-based Multi-Factor Authentication (like Google Authenticator) rather than SMS.
: Session tokens that allow attackers to bypass 2FA and hijack accounts.
Mavis Hotels