logo

Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption

ID: e2b7cc69-621f-5491-a3cc-d8ed478a2e67

STIX ID: report--e2b7cc69-621f-5491-a3cc-d8ed478a2e67

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-24

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

- Tycoon2FA, a subscription-based phishing-as-a-service platform that performs AITM MFA bypasses, rapidly recovered after a March 4, 2026 domain seizure and resumed large-scale cloud account compromises; the report documents persistent campaigns that steal session cookies and MFA tokens to automate logins to Microsoft EntraID accounts. It highlights tactics including obfuscated JavaScript proxying, geofencing with AI-generated decoys, use of URL shorteners and compromised SharePoint links, rapid acquisition of IPv6 infrastructure, and recommendations such as conditional access policies, monitoring of inbox rules, DNS/authentication logs, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.