Tycoon2FA Phishing Service Resumes Activity Post-Takedown
ID: 38d7a547-eb82-51c8-9544-e82a57efdc7b
STIX ID: report--38d7a547-eb82-51c8-9544-e82a57efdc7b
Feed Name: Infosecurity Magazine (News)
Tycoon2FA, a subscription phishing-as-a-service that leverages adversary-in-the-middle attacks to bypass MFA, was briefly disrupted by a Europol-coordinated takedown that seized 330 domains, but activity quickly resumed; the platform has been linked to large-scale phishing (reported as ~62% of blocked attempts and ~30 million malicious emails in a month) and continues to deploy compromised domains, legitimate cloud service redirection, IPv6 automation, and AI-generated decoy pages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
