logo

Dadsec Hackers Exploit Tycoon2FA Infrastructure to Harvest Office365 Credentials

ID: ffbe8119-2353-5ce4-9682-97813d447d76

STIX ID: report--ffbe8119-2353-5ce4-9682-97813d447d76

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-05-30

Date Updated: 2026-04-19

Author: Mandvi

...
...

Trustwave intelligence reports convergence between the Dadsec Phishing-as-a-Service (PhaaS) platform and the Tycoon2FA kit—linked to Storm-1575—using shared infrastructure (notably AS19871), randomized domains (including .ru TLDs), and recurring PHP artifacts (e.g., res444.php, cllascio.php) to deploy sophisticated AiTM phishing pages that capture Office365 credentials and session cookies, bypass MFA, and employ Cloudflare Turnstile and anti-analysis controls to scale campaigns and hinder research; organizations are advised to enhance monitoring, email filtering, and user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.