logo

Tycoon 2FA credential phishing with cloned internal employee login · Blog · Sublime Security

ID: 6a9e73f3-925d-56b8-83da-401c8915ceae

STIX ID: report--6a9e73f3-925d-56b8-83da-401c8915ceae

Feed Name: Sublime Security Blog

Threat Score
65/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

This Attack Spotlight details a Tycoon 2FA phishing-as-a-service campaign that used a malicious PDF containing a QR code to direct targets through Cloudflare Turnstile to a recycled fake SharePoint voicemail page and an adversary-in-the-middle cloned login to capture credentials; Sublime detected and blocked the attack and published detection rules highlighting signals such as QR codes with phishing disposition, empty message bodies, and newly-registered sender domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.