logo

Tycoon2FA Phishing-as-a-Service Platform Persists Following Takedown

ID: f9771b56-c01d-5fe7-aa69-9817bc96f688

STIX ID: report--f9771b56-c01d-5fe7-aa69-9817bc96f688

Feed Name: Crowdstrike Blog

Threat Score
78/100

Date Published: 2026-03-20

Date Updated: 2026-04-27

Author: Falcon Complete Team - Counter Adversary Operations

...
...

On March 4, 2026 Europol and international partners disrupted Tycoon2FA — a subscription-based PhaaS that used AITM to intercept authentication sessions and bypass MFA — by seizing 330 domains; CrowdStrike observed an initial decline in activity followed by a rapid return to pre-takedown cloud compromise levels, documenting persistent TTPs, numerous phishing domains, and diverse post-disruption phishing techniques that continue to pose significant risk to cloud/email environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.