logo

New MFA-bypassing phishing kit targets Microsoft 365, Gmail accounts

ID: 2e24c360-a733-568a-9c68-0261cef6c26c

STIX ID: report--2e24c360-a733-568a-9c68-0261cef6c26c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-03-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A newly observed phishing-as-a-service platform called Tycoon 2FA is actively enabling adversaries to bypass MFA for Microsoft 365 and Gmail by using a reverse-proxy AitM approach to capture session cookies; the kit has evolved to include stealth and anti-bot measures, is deployed across ~1,100 domains and thousands of attacks, and has monetized via cryptocurrency payments, with IoCs published by Sekoia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.