Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption
ID: e2b7cc69-621f-5491-a3cc-d8ed478a2e67
STIX ID: report--e2b7cc69-621f-5491-a3cc-d8ed478a2e67
Feed Name: cybersecurityNews.com
- Tycoon2FA, a subscription-based phishing-as-a-service platform that performs AITM MFA bypasses, rapidly recovered after a March 4, 2026 domain seizure and resumed large-scale cloud account compromises; the report documents persistent campaigns that steal session cookies and MFA tokens to automate logins to Microsoft EntraID accounts. It highlights tactics including obfuscated JavaScript proxying, geofencing with AI-generated decoys, use of URL shorteners and compromised SharePoint links, rapid acquisition of IPv6 infrastructure, and recommendations such as conditional access policies, monitoring of inbox rules, DNS/authentication logs, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
