logo

Tycoon 2FA phishing actors disperse, branch into new attacks | Threat Intelligence

ID: 273e86a2-f71c-523e-90a2-46dd7d8a57f1

STIX ID: report--273e86a2-f71c-523e-90a2-46dd7d8a57f1

Feed Name: Threat Intelligence | Blog | Okta

Threat Score
78/100

Date Published: 2026-05-02

Date Updated: 2026-07-16

Author: Houssem Eddine Bordjiba, Daniel López, Jeremy Kirk

...
...

Tycoon 2FA is a widely observed phishing kit that operated as a transparent reverse proxy to capture session tokens and relay MFA challenges, allowing attackers to replay tokens and bypass both login and MFA for account takeover; Okta telemetry shows thousands of attempted phishes at peak and continued detections after a takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.