Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
ID: 9dbb0f04-7059-5851-88c8-c0b3e91be1e8
STIX ID: report--9dbb0f04-7059-5851-88c8-c0b3e91be1e8
Feed Name: Microsoft Security
Date Published: 2026-03-04
Date Updated: 2026-04-28
Author: Microsoft Threat Intelligence and Microsoft Defender Security Research Team
Tycoon2FA is a widely deployed phishing‑as‑a‑service platform that enables AiTM phishing campaigns able to intercept credentials and session cookies to bypass MFA at scale; the report describes the service panel, infrastructure and URL patterns, common email lures and attachment types, extensive evasion techniques (custom CAPTCHAs, obfuscated JS, redirect chains), examples of exfiltration (Telegram bots), Microsoft Defender detections and hunting queries, and recommended mitigations including phishing‑resistant authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
