Tycoon2FA phishing platform returns after recent police disruption
ID: 0d2e4223-6fd6-5623-b467-ea0394dbfbcd
STIX ID: report--0d2e4223-6fd6-5623-b467-ea0394dbfbcd
Feed Name: Bleeping Computer
Tycoon2FA, a phishing-as-a-service platform that targets Microsoft 365 and Gmail using adversary-in-the-middle 2FA bypass techniques, was temporarily disrupted by law enforcement (330 domains seized) but returned to prior operational volumes within days. CrowdStrike observed resumed phishing campaigns that support business email compromise, cloud account takeovers, and other fraud, using malicious URLs, URL shorteners, abused legitimate platforms, and compromised domains; post-compromise activity includes inbox rules and hidden folders to facilitate fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
