logo

Tycoon2FA Operators Resume Cloud Account Phishing Following Infrastructure

ID: 2e541994-0ab2-5be1-95f9-dcb27ed8ea10

STIX ID: report--2e541994-0ab2-5be1-95f9-dcb27ed8ea10

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-24

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report describes Tycoon2FA, a prolific phishing-as-a-service (PhaaS) platform that leverages adversary-in-the-middle techniques to intercept MFA-protected Microsoft 365 and Google sessions and facilitate large-scale cloud account takeover and BEC campaigns. Despite a coordinated Europol-led domain seizure, Tycoon2FA operators and customers rapidly restored operations by registering new domains and addresses, continuing prior tactics such as CAPTCHA decoys, session cookie theft, compromised redirects, and hosting on abused cloud services; the report includes example domains, observed behaviors, and recommendations for continuous identity- and email-layer visibility and rapid response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.