Tycoon 2FA: an in-depth analysis of the latest version of the AiTM phishing kit
ID: 7b6f2613-c294-51fa-acb8-d98308f6727a
STIX ID: report--7b6f2613-c294-51fa-acb8-d98308f6727a
Feed Name: Sekoia.com
Sekoia TDR identified and analysed Tycoon 2FA, an Adversary-in-the-Middle phishing kit offered as Phishing-as-a-Service since at least August 2023; the kit uses Cloudflare Turnstile checks, heavily obfuscated JavaScript, WebSocket exfiltration and relaying to capture Microsoft 365 credentials and session cookies (enabling MFA bypass). The report documents the kit's multi-stage workflow, infrastructure and IoCs (over 1,100+ domains observed), updated stealth/evasion tactics in a February 2024 release, tracking heuristics, and a Bitcoin address linked to the operator, concluding the service is widely used and financially lucrative.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
