Tycoon2FA Phishing-as-a-Service Platform Persists Following Takedown
ID: f9771b56-c01d-5fe7-aa69-9817bc96f688
STIX ID: report--f9771b56-c01d-5fe7-aa69-9817bc96f688
Feed Name: Crowdstrike Blog
Date Published: 2026-03-20
Date Updated: 2026-04-27
Author: Falcon Complete Team - Counter Adversary Operations
On March 4, 2026 Europol and international partners disrupted Tycoon2FA — a subscription-based PhaaS that used AITM to intercept authentication sessions and bypass MFA — by seizing 330 domains; CrowdStrike observed an initial decline in activity followed by a rapid return to pre-takedown cloud compromise levels, documenting persistent TTPs, numerous phishing domains, and diverse post-disruption phishing techniques that continue to pose significant risk to cloud/email environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
