Dadsec Hackers Exploit Tycoon2FA Infrastructure to Harvest Office365 Credentials
ID: ffbe8119-2353-5ce4-9682-97813d447d76
STIX ID: report--ffbe8119-2353-5ce4-9682-97813d447d76
Feed Name: Cyber Press
Trustwave intelligence reports convergence between the Dadsec Phishing-as-a-Service (PhaaS) platform and the Tycoon2FA kit—linked to Storm-1575—using shared infrastructure (notably AS19871), randomized domains (including .ru TLDs), and recurring PHP artifacts (e.g., res444.php, cllascio.php) to deploy sophisticated AiTM phishing pages that capture Office365 credentials and session cookies, bypass MFA, and employ Cloudflare Turnstile and anti-analysis controls to scale campaigns and hinder research; organizations are advised to enhance monitoring, email filtering, and user awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
