logo

'Tycoon' Malware Kit Bypasses Microsoft, Google MFA

ID: afa01a72-201a-5a02-8fff-f9fd28a1e944

STIX ID: report--afa01a72-201a-5a02-8fff-f9fd28a1e944

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-03-27

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Tycoon 2FA is an active adversary-in-the-middle phishing-as-a-service sold via Telegram that targets Microsoft 365 and Gmail to bypass multi-factor authentication by harvesting session cookies; the report details the kit’s six-stage attack flow, widespread distribution (1,100+ domains), pricing and operator information, enhanced obfuscation/anti-detection features, and published IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.