Tycoon 2FA credential phishing with cloned internal employee login · Blog · Sublime Security
ID: 6a9e73f3-925d-56b8-83da-401c8915ceae
STIX ID: report--6a9e73f3-925d-56b8-83da-401c8915ceae
Feed Name: Sublime Security Blog
Threat Score
This Attack Spotlight details a Tycoon 2FA phishing-as-a-service campaign that used a malicious PDF containing a QR code to direct targets through Cloudflare Turnstile to a recycled fake SharePoint voicemail page and an adversary-in-the-middle cloned login to capture credentials; Sublime detected and blocked the attack and published detection rules highlighting signals such as QR codes with phishing disposition, empty message bodies, and newly-registered sender domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
