logo

Tycoon 2FA AiTM Kit Targets Entra ID and Google Workspace In MFA Bypass Campaigns

ID: 6c446760-6625-5f75-bd81-7f2b54979fad

STIX ID: report--6c446760-6625-5f75-bd81-7f2b54979fad

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Varshini

...
...

The Tycoon 2FA Phishing-as-a-Service (PhaaS) platform has resumed operations after a coordinated takedown, employing adversary-in-the-middle proxies and OAuth device-code phishing to capture post-MFA session tokens and bypass multi-factor authentication for Microsoft 365 and Google Workspace; operators use WebSocket relays, rogue device registration to obtain persistent Primary Refresh Tokens (PRTs), and abuse legitimate cloud storage for hosting phishing lures, while implementing layered anti-analysis and targeted infrastructure differences per provider.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.