'Tycoon' Malware Kit Bypasses Microsoft, Google MFA
ID: afa01a72-201a-5a02-8fff-f9fd28a1e944
STIX ID: report--afa01a72-201a-5a02-8fff-f9fd28a1e944
Feed Name: Dark Reading
Threat Score
Date Published: 2024-03-27
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
...
...
Tycoon 2FA is an active adversary-in-the-middle phishing-as-a-service sold via Telegram that targets Microsoft 365 and Gmail to bypass multi-factor authentication by harvesting session cookies; the report details the kit’s six-stage attack flow, widespread distribution (1,100+ domains), pricing and operator information, enhanced obfuscation/anti-detection features, and published IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
