logo

Tycoon 2FA Phishing Kit Analysis

ID: da229847-3e7e-5f11-9656-c864ece3c657

STIX ID: report--da229847-3e7e-5f11-9656-c864ece3c657

Feed Name: Cybereason Blog

Threat Score
78/100

Date Published: 2025-11-03

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

This report analyzes the Tycoon 2FA phishing kit, a sophisticated AiTM Phishing-as-a-Service active since August 2023 that bypasses MFA to steal Microsoft 365 and Gmail credentials and session tokens via reverse-proxied fake login pages. It details wide distribution channels (PDFs, SVGs, PPTs, emails, cloud hosting), multi-stage obfuscated JavaScript (base64, LZ-string, CryptoJS/AES, XOR), debugger and bot checks, C2 endpoints, and recommended mitigations such as user training, stronger MFA, and anti-phishing solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.