logo

Tycoon 2FA: an in-depth analysis of the latest version of the AiTM phishing kit

ID: ecc1239f-7594-5fba-98df-30b9cd907feb

STIX ID: report--ecc1239f-7594-5fba-98df-30b9cd907feb

Feed Name: Sekoia.io Blog

Threat Score
75/100

Date Published: 2024-03-25

Date Updated: 2026-04-29

Author: Quentin Bourgue and TDR (Threat Detection & Research)

...
...

**Executive summary:** Sekoia analysts discovered and analyzed Tycoon 2FA, an AiTM phishing kit marketed as a Phishing‑as‑a‑Service (PhaaS) that has been active since at least August 2023 and used in widespread campaigns; the kit relays Microsoft 365 authentications (including MFA) via a reverse proxy to harvest credentials and session cookies, employs Cloudflare Turnstile and obfuscated JavaScript/WebSocket exfiltration to evade detection, and is linked to over a thousand domains and a Bitcoin wallet indicating active monetization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.