logo

Tycoon 2FA phishing actors disperse, branch into new attacks | Threat Intelligence

ID: df60f5db-74a6-554f-b60e-2fb842454182

STIX ID: report--df60f5db-74a6-554f-b60e-2fb842454182

Feed Name: Okta Threat Intelligence

Threat Score
78/100

Date Published: 2026-05-02

Date Updated: 2026-08-05

Author: Houssem Eddine Bordjiba, Daniel López, Jeremy Kirk

...
...

Tycoon 2FA is a phishing kit that operates as a transparent reverse proxy to pass credentials and MFA challenges to legitimate services, capture session tokens returned to the browser, and enable session-token replay to bypass both login and MFA. Okta telemetry shows it became the most-observed AitM phishing kit by mid-2025 with thousands of detections (e.g., 11,199 detections in July 2025), a takedown on March 4, 2026, and continued detections after the takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.