Tycoon 2FA Phishing Kit Upgraded to Bypass Security Measures
ID: 5b013b67-7cdf-53b1-8991-b38dcde8aa8c
STIX ID: report--5b013b67-7cdf-53b1-8991-b38dcde8aa8c
Feed Name: Infosecurity Magazine (News)
Barracuda researchers analyzed an updated Tycoon 2FA phishing kit that emerged in November 2024 and targets Microsoft 365 session cookies to bypass multi-factor authentication. The kit uses compromised legitimate email accounts, obfuscated and obstructive source code, automated script detection (including blocking penetration-testing tools), keystroke/listener checks for developer tools, right-click disabling, clipboard overwrites, and redirects to legitimate sites when developer tools are detected, all to evade detection and analysis. Barracuda highlights the growing role of Phishing-as-a-Service in credential attacks and recommends layered defenses and continuously evolving security tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
