Tycoon 2FA AiTM Kit Targets Entra ID and Google Workspace In MFA Bypass Campaigns
ID: 6c446760-6625-5f75-bd81-7f2b54979fad
STIX ID: report--6c446760-6625-5f75-bd81-7f2b54979fad
Feed Name: Cyber Press
The Tycoon 2FA Phishing-as-a-Service (PhaaS) platform has resumed operations after a coordinated takedown, employing adversary-in-the-middle proxies and OAuth device-code phishing to capture post-MFA session tokens and bypass multi-factor authentication for Microsoft 365 and Google Workspace; operators use WebSocket relays, rogue device registration to obtain persistent Primary Refresh Tokens (PRTs), and abuse legitimate cloud storage for hosting phishing lures, while implementing layered anti-analysis and targeted infrastructure differences per provider.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
