Tycoon2FA Operators Resume Cloud Account Phishing Following Infrastructure
ID: 2e541994-0ab2-5be1-95f9-dcb27ed8ea10
STIX ID: report--2e541994-0ab2-5be1-95f9-dcb27ed8ea10
Feed Name: GBHackers
The report describes Tycoon2FA, a prolific phishing-as-a-service (PhaaS) platform that leverages adversary-in-the-middle techniques to intercept MFA-protected Microsoft 365 and Google sessions and facilitate large-scale cloud account takeover and BEC campaigns. Despite a coordinated Europol-led domain seizure, Tycoon2FA operators and customers rapidly restored operations by registering new domains and addresses, continuing prior tactics such as CAPTCHA decoys, session cookie theft, compromised redirects, and hosting on abused cloud services; the report includes example domains, observed behaviors, and recommendations for continuous identity- and email-layer visibility and rapid response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
