Threats Tagged 'tycoon2fa'
View all threats tagged with 'tycoon2fa'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'tycoon2fa'
Click on any threat for detailed analysis and mitigation recommendations
During Q2 2026, Microsoft detected approximately 7.6 billion email-based phishing threats, with monthly volumes declining from 2.7 billion in April to 2.4 billion in June. The quarter was significantly shaped by the downstream effects of Microsoft's Digital Crimes Unit disruption of the Tycoon2FA phishing-as-a-service platform in March, resulting in a 92% decline in associated phishing volume. QR code phishing attacks peaked at 18.7 monthly attacks in March before declining 48% by June, while CAPTCHA-gated phishing fell 81% from its March high. Credential phishing remained the dominant objective, accounting for 94-96% of all payload-based attacks. Business email compromise activity returned to historical norms after an anomalous April surge. Microsoft Teams-based threats grew substantially, with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by quarter end. Join the discussion | AlienVault OTX General | 07/23/2026, 16:30:34 UTC Added: 07/23/2026, 23:37:06 UTC |
Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion. Join the discussion | AlienVault OTX General | 07/15/2026, 01:40:05 UTC Added: 07/15/2026, 14:19:07 UTC |
Tycoon2FA emerged as a prominent phishing-as-a-service platform in August 2023, enabling large-scale campaigns targeting over 500,000 organizations monthly. Developed by Storm-1747, it provided adversary-in-the-middle capabilities to bypass multifactor authentication. The kit allowed impersonation of trusted brands like Microsoft 365 and Gmail, intercepting session cookies and credentials. It employed sophisticated evasion techniques including anti-bot screening, browser fingerprinting, and custom CAPTCHAs. Tycoon2FA's infrastructure evolved to use diverse, short-lived domains and complex redirect chains. Its success stemmed from closely mimicking legitimate authentication processes while covertly intercepting user credentials and session tokens. MediumMalware Join the discussion | AlienVault OTX General | 03/04/2026, 19:42:43 UTC Added: 03/05/2026, 09:37:49 UTC |
Threat actors are leveraging complex routing scenarios and misconfigured spoof protections to send phishing emails that appear to be internal communications. These attacks, which have increased since May 2025, use various lures like voicemails, shared documents, and password resets to conduct credential phishing and financial scams. The campaigns, often using PhaaS platforms like Tycoon2FA, are opportunistic and target multiple industries. While Microsoft detects most attempts, organizations can further mitigate risks by properly configuring spoof protections and third-party connectors. The attacks do not affect customers whose Microsoft Exchange MX records point to Office 365, as they are protected by built-in spoofing detections. Join the discussion | AlienVault OTX General | 01/07/2026, 11:34:32 UTC Added: 01/07/2026, 11:52:02 UTC |
A hybrid phishing threat combining Salty2FA and Tycoon2FA phishing kits has emerged, leveraging code and infrastructure from both frameworks. This hybridization appears driven by Salty2FA infrastructure failures, causing fallback to Tycoon2FA hosting and payload delivery. The overlap complicates attribution and weakens detection rules tailored to either kit alone. The threat is linked to the Storm-1747 adversary group, known for Tycoon2FA operations. Indicators include multiple suspicious domains used for hosting phishing pages. Defenders should update detection logic to address cross-kit overlaps and prepare for more resilient phishing campaigns that can adapt to infrastructure disruptions. The threat is rated medium severity and does not require exploits in the wild or CVSS scoring. European organizations should be vigilant due to the widespread use of 2FA and phishing susceptibility. Mitigation requires tailored detection updates, domain monitoring, and user awareness enhancements. Join the discussion | AlienVault OTX General | 12/02/2025, 21:13:43 UTC Added: 12/03/2025, 11:15:39 UTC |
In August 2025, significant cyber attacks emerged, including a 7-stage Tycoon2FA phishing campaign targeting government, military, and financial institutions across the US, UK, Canada, and Europe. The attack uses multiple verification steps to evade security systems. A new ClickFix campaign delivered the Rhadamanthys Stealer using PNG steganography, indicating increased sophistication in payload delivery. Salty2FA, a new Phishing-as-a-Service framework attributed to Storm-1575, was discovered targeting Microsoft 365 accounts globally, capable of bypassing various 2FA methods. These attacks demonstrate the evolution of phishing kits and stealers, emphasizing the need for behavioral analysis and real-time threat intelligence in cybersecurity defenses. Join the discussion | AlienVault OTX General | 08/26/2025, 16:14:13 UTC Added: 08/26/2025, 18:47:48 UTC |
This analysis explores the connections between two Phishing-as-a-Service (PhaaS) platforms: Tycoon2FA and Dadsec. The investigation reveals shared infrastructure and operational similarities, suggesting a common origin or adaptation. The report details the evolving tactics of Tycoon2FA, including its use of Cloudflare Turnstile, anti-analysis techniques, and sophisticated phishing pages. Key findings include the rapid expansion of Tycoon2FA's infrastructure, with thousands of new phishing pages detected since July 2024. The analysis also uncovers the platform's advanced features, such as MFA bypass capabilities and real-time credential interception. The report emphasizes the growing threat posed by PhaaS platforms and the need for continued vigilance and adaptation in cybersecurity defenses. Join the discussion | AlienVault OTX General | 05/29/2025, 16:10:37 UTC Added: 05/29/2025, 19:29:21 UTC |
Showing 1 to 7 of 7 results