{"id":60261,"date":"2026-03-04T16:04:24","date_gmt":"2026-03-04T16:04:24","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=145441"},"modified":"2026-03-04T16:04:24","modified_gmt":"2026-03-04T16:04:24","slug":"inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/","title":{"rendered":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale"},"content":{"rendered":"<aside class=\"table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents\" id=\"accordion-53f830ff-890a-42a5-a990-122a9590ac3c\" data-bi-an=\"table-of-contents\"> <button class=\"btn btn-collapse\" type=\"button\" aria-expanded=\"true\" aria-controls=\"accordion-collapse-53f830ff-890a-42a5-a990-122a9590ac3c\"> <span class=\"table-of-contents-block__label\">In this article<\/span> <span class=\"table-of-contents-block__current\" aria-hidden=\"true\"><\/span> <svg class=\"table-of-contents-block__arrow\" aria-label=\"Toggle arrow\" width=\"18\" height=\"11\" viewBox=\"0 0 18 11\" fill=\"none\"> <path d=\"M15.7761 11L18 8.82043L9 0L0 8.82043L2.22394 11L9 4.35913L15.7761 11Z\" fill=\"currentColor\" \/> <\/svg> <\/button> <span class=\"table-of-contents-block__progress-bar\"><\/span><br \/>\n<\/aside>\n<p class=\"wp-block-paragraph\">Following its emergence in August 2023, Tycoon2FA rapidly became one of the most widespread phishing-as-a-service (PhaaS) platforms, enabling campaigns responsible for tens of millions of phishing messages reaching over 500,000 organizations each month worldwide. The phishing kit\u2014developed, supported, and advertised by the threat actor tracked by Microsoft Threat Intelligence as Storm-1747\u2014provided adversary-in-the-middle (AiTM) capabilities that allowed even less skilled threat actors to bypass multifactor authentication (MFA), significantly lowering the barrier to conducting account compromise at scale.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp\" alt=\"Column chart showing monthly volume of Tycoon2FA-realted phishing messages from October 2025 to January 2026\" class=\"wp-image-145454 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp\"><figcaption class=\"wp-element-caption\">Figure 1. Monthly volume of Tycoon2FA-related phishing messages<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Tycoon2FA\u2019s platform enabled threat actors to impersonate trusted brands by mimicking sign-in pages for services like Microsoft 365, OneDrive, Outlook, SharePoint, and Gmail. It also allowed threat actors using its service to establish persistence and to access sensitive information even after passwords are reset, unless active sessions and tokens were explicitly revoked. This worked by intercepting session cookies generated during the authentication process, simultaneously capturing user credentials. The MFA codes were subsequently relayed through Tycoon2FA\u2019s proxy servers to the authenticating service.<\/p>\n<p class=\"wp-block-paragraph\">To evade detection, Tycoon2FA used techniques like anti-bot screening, browser fingerprinting, heavy code obfuscation, self-hosted CAPTCHAs, custom JavaScript, and dynamic decoy pages. Targets are often lured through phishing emails containing attachments like <em>.svg, .pdf, .html,<\/em> or <em>.docx<\/em> files, often embedded with QR codes or JavaScript.<\/p>\n<p class=\"wp-block-paragraph\">This blog provides a comprehensive up-to-date analysis of Tycoon2FA\u2019s progression and scale. We share specific examples of the Tycoon2FA service panel, including a detailed analysis of Tycoon2FA infrastructure. Defending against Tycoon2FA and similar AiTM phishing threats requires a layered approach that blends technical controls with user awareness. This blog also provides <a href=\"https:\/\/www.microsoft.com\/security\/business\/microsoft-defender\">Microsoft Defender<\/a> detection and hunting guidance, as well as resources on how to set up mail flow rules, enforce spoof protections, and configure third-party connectors to prevent spoofed phishing messages from reaching user inboxes.<\/p>\n<h2 class=\"wp-block-heading\" id=\"operational-overview-of-tycoon2fa\">Operational overview of Tycoon2FA<\/h2>\n<h3 class=\"wp-block-heading\" id=\"tycoon2fa-customer-panel\">Tycoon2FA customer panel<\/h3>\n<p class=\"wp-block-paragraph\">Tycoon2FA phishing services were advertised and sold to cybercriminals on applications like Telegram and Signal. Phish kits were observed to start at $120 USD for access to the panel for 10 days and $350 for access to the panel for a month, but these prices could vary.<\/p>\n<p class=\"wp-block-paragraph\">Tycoon2FA is operated through a web\u2011based administration panel provided on a per user basis that centrally integrates all functionality provided by the Tycoon2FA PhaaS platform. The panel serves as a single dashboard for configuring, tracking, and refining campaigns. While it does not include built\u2011in mailer capabilities, the panel provides the core components needed to support phishing campaigns. This includes pre\u2011built templates, attachment files for common lure formats, domain and hosting configuration, redirect logic, and victim tracking. This design makes the platform accessible to less technically skilled actors while still offering sufficient flexibility for more experienced operators.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig2-admin-panel.webp\" alt=\"Screenshot of Tycoon2FA admin panel-sign-in screen\" class=\"wp-image-145455 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig2-admin-panel.webp\"><figcaption class=\"wp-element-caption\">Figure 2. Tycoon2FA admin panel sign-in screen<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">After signing in, Tycoon2FA customers are presented with a dashboard used to configure, monitor, and manage phishing campaigns. Campaign operators can configure a broad set of campaign parameters that control how phishing content is delivered and presented to targets. Key settings include lure template selection and branding customization, redirection routing, MFA interception behavior, CAPTCHA appearance and logic, attachment generation, and exfiltration configuration. Campaign operators can choose from highly configurable landing pages and sign-in themes that impersonate widely trusted services such as Microsoft 365, Outlook, SharePoint, OneDrive, and Google, increasing the perceived legitimacy of attacks.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig3-phishing-page-theme-scaled.webp\" alt=\"Screenshot of phishing page them selection and configuration settings in the Tycoon2FA admin panel\" class=\"wp-image-145498 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig3-phishing-page-theme-scaled.webp\"><figcaption class=\"wp-element-caption\">Figure 3. Phishing page theme selection and configuration settings<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Campaign operators can also configure how the malicious content is delivered through attachments. Options include generating EML files, PDFs, and QR codes, offering multiple ways to package and distribute phishing lures.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig4-malicious-attachment-options.webp\" alt=\"Screenshot of malicious attachment options in the Tycoon2FA admin panel\" class=\"wp-image-145457 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig4-malicious-attachment-options.webp\"><figcaption class=\"wp-element-caption\">Figure 4. Malicious attachment options<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The panel also allows operators to manage redirect chains and routing logic, including the use of intermediate pages and decoy destinations. Support for automated subdomain rotation and intermediary Cloudflare Workers-based URLs enables campaigns to adapt quickly as infrastructure is identified or blocked. The following is a visual example of redirect and routing options, including intermediate pages and decoy destinations used within a phishing campaign.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig5-redirect-chain-routing-configuration.webp\" alt=\"Screenshot of redirect chain and routing configuration settings in the Tycoon2FA admin panel\" class=\"wp-image-145458 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig5-redirect-chain-routing-configuration.webp\"><figcaption class=\"wp-element-caption\">Figure 5. Redirect chain and routing configuration<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Once configured, these settings control the appearance and behavior of the phishing pages delivered to targets. The following examples show how selected themes (Microsoft 365 and Outlook) are rendered as legitimate-looking sign-in pages presented to targets.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig6.webp\" alt=\"Screenshot of a Tycoon2FA phishing page\" class=\"wp-image-145459 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig6.webp\"><\/figure>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig6-b-sample-phishing-pages.webp\" alt=\"Screenshot of a Tycoon2FA phishing page\" class=\"wp-image-145460 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig6-b-sample-phishing-pages.webp\"><figcaption class=\"wp-element-caption\">Figure 6. Sample Tycoon2FA phishing pages<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Beyond campaign configuration, the panel provides detailed visibility into victim interaction and authentication outcomes. Operators can track valid and invalid sign-in attempts, MFA usage, and session cookie capture, with victim data organized by attributes such as targeted service, browser, location, and authentication status. Captured credentials and session cookies can be viewed or downloaded directly within the panel and\/or forwarded to Telegram for near\u2011real\u2011time monitoring. The following image shows a summary view of victim account outcomes for threat actors to review and track.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig7-panel-dashboard-1.webp\" alt=\"Screenshot of Tycoon2FA panel dashboard\" class=\"wp-image-145462 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig7-panel-dashboard-1.webp\"><figcaption class=\"wp-element-caption\">Figure 7. Tycoon2FA panel dashboard<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Captured session information including account attributes, browsers and location metadata, and authentication artifacts are exfiltrated through Telegram bot.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig8-exfiltrated-session-information.webp\" alt=\"Screenshot of exfiltrated session information through Telegram\" class=\"wp-image-145463 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig8-exfiltrated-session-information.webp\"><figcaption class=\"wp-element-caption\">Figure 8. Exfiltrated session information<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">In addition to configuration and campaign management features, the panel includes a section for announcements and updates related to the service. These updates reflect regular maintenance and ongoing changes, indicating that the service continues to evolve.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig9-tycoon2fa-announcement-update-panel.webp\" alt=\"Screenshot of announcement and update info in the Tycoon2FA admin panel\" class=\"wp-image-145464 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig9-tycoon2fa-announcement-update-panel.webp\"><figcaption class=\"wp-element-caption\">Figure 9. Tycoon2FA announcement and update panel<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">By combining centralized configuration, real-time visibility, and regular platform updates, the service enables scalable AiTM phishing operations that can adapt quickly to defensive measures. This balance of usability, adaptability, and sustained development has contributed to Tycoon2FA\u2019s adoption across a wide range of campaigns.<\/p>\n<h3 class=\"wp-block-heading\" id=\"tycoon2fa-infrastructure\">Tycoon2FA infrastructure<\/h3>\n<p class=\"wp-block-paragraph\">Tycoon2FA\u2019s infrastructure has shifted from static, high-entropy domains to a fast-moving ecosystem with diverse top-level domains (TLDs) and short-lived (often 24-72 hours) fully qualified domain names (FQDNs), with the majority hosted on Cloudflare. A key change is the move toward a broader mix of TLDs. Early tracking showed heavier use of regional TLDs like <em>.es<\/em> and <em>.ru<\/em>, but recent campaigns increasingly rotated across inexpensive generic TLDs that require little to no identity verification. Examples include .<em>space<\/em>, .<em>email<\/em>, .<em>solutions<\/em>, .<em>live<\/em>, .<em>today<\/em>, and .<em>calendar<\/em>, as well as second-level domains such as .<em>sa[.]com<\/em>, .<em>in[.]net<\/em>, and .<em>com[.]de<\/em>.<\/p>\n<p class=\"wp-block-paragraph\">Tycoon2FA generated large numbers of subdomains for individual phishing campaigns, used them briefly, then dropped them and spun up new ones. Parent root domains might remain registered for weeks or months, but nearly all campaign-specific FQDNs were temporary. The rapid turnover complicated detection efforts, such as building reliable blocklists or relying on reputation-based defenses.<\/p>\n<p class=\"wp-block-paragraph\">Subdomain patterns have also shifted toward more readable formats. Instead of high entropy or algorithmically generated strings, like those used in July 2025, newly observed subdomains used recognizable words tied to common workflows or services, like those observed in December 2025.<\/p>\n<p class=\"wp-block-paragraph\">July 2025 campaign URL structure examples:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/qonnfp.wnrathttb[.]ru\/Fe2yiyoKvg3YTfV!\/$EMAIL_ADDRESS<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/piwf.ariitdc[.]es\/kv2gVMHLZ@dNeXt\/$EMAIL_ADDRESS<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/q9y3.efwzxgd[.]es\/MEaap8nZG5A@c8T\/*EMAIL_ADDRESS<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/kzagniw[.]es\/LI6vGlx7@1wPztdy<\/em><\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">December 2025 campaign URL structure examples:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/immutable.nathacha[.]digital\/T@uWhi6jqZQH7\/#?EMAIL_ADDRESS<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/mock.zuyistoo[.]today\/pry1r75TisN5S@8yDDQI\/$EMAIL_ADDRESS<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/astro.thorousha[.]ru\/vojd4e50fw4o!g\/$ENCODED EMAIL_ADDRESS<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/branch.cricomai[.]sa[.]com\/b@GrBOPttIrJA\/*EMAIL_ADDRESS<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/mysql.vecedoo[.]online\/JB5ow79@fKst02\/#EMAIL_ADDRESS<\/em><\/li>\n<li class=\"wp-block-list-item\"><em>hxxps:\/\/backend.vmfuiojitnlb[.]es\/CGyP9!CbhSU22YT2\/<\/em><\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Some subdomains resembled everyday processes or tech terms like <em>cloud<\/em>, <em>desktop<\/em>, <em>application<\/em>, and <em>survey<\/em>, while others echoed developer or admin vocabulary like <em>python<\/em>, <em>terminal<\/em>, <em>xml<\/em>, and <em>faq<\/em>. Software as a service (SaaS) brand names have appeared in subdomains as well, such as <em>docker<\/em>, <em>zendesk<\/em>, <em>azure<\/em>, <em>microsoft<\/em>, <em>sharepoint<\/em>, <em>onedrive,<\/em> and <em>nordvpn<\/em>. This shift was likely used to reduce user suspicion and to evade detection models that rely on entropy or string irregularity.<\/p>\n<p class=\"wp-block-paragraph\">Tycoon2FA\u2019s success stemmed from closely mimicking legitimate authentication processes while covertly intercepting both user credentials and session tokens, granting attackers full access to targeted accounts. Tycoon2FA operators could bypass nearly all commonly deployed MFA methods, including SMS codes, one-time passcodes, and push notifications. The attack chain was typical yet highly effective and started with phishing the user through email, followed by a multilayer redirect chain, then a spoofed sign-in page with AiTM relay, and authentication relay culminating in token theft.<\/p>\n<h3 class=\"wp-block-heading\" id=\"tycoon2fa-phishing-emails\">Tycoon2FA phishing emails<\/h3>\n<p class=\"wp-block-paragraph\">In observed campaigns, threat actors gained initial access through phishing emails that used either embedded links or malicious attachments. Most of Tycoon2FA\u2019s lures fell into four categories:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">PDF or DOC\/DOCX attachments with QR codes<\/li>\n<li class=\"wp-block-list-item\">SVG files containing embedded redirect logic<\/li>\n<li class=\"wp-block-list-item\">HTML attachments with short messages<\/li>\n<li class=\"wp-block-list-item\">Redirect links that appear to come from trusted services<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Email lures were crafted from ready-made templates that impersonated trusted business applications like Microsoft 365, Azure, Okta, OneDrive, Docusign, and SharePoint. These templates spanned themes from generic notifications (like voicemail and shared document access) to targeted workflows (like human resources (HR) updates, corporate documents, and financial statements). In addition to spoofing trusted brands, phishing emails often leveraged compromised accounts with existing threads to increase legitimacy.<\/p>\n<p class=\"wp-block-paragraph\">While Tycoon2FA supplied hosting infrastructures, along with various phishing and landing page related templates, email distribution was not provided by the service.<\/p>\n<h3 class=\"wp-block-heading\" id=\"defense-evasion\">Defense evasion<\/h3>\n<p class=\"wp-block-paragraph\">From a defense standpoint, Tycoon2FA stood out for its continuously updated evasion and attack techniques. A defining feature was the use of constantly changing custom CAPTCHA pages that regenerated frequently and varied across campaigns. As a result, static signatures and narrowly scoped detection logic became less effective over time. Before credentials were entered, targets encounter the custom CAPTCHA challenge, which was designed to block automated scanners and ensure real users reach the phishing content. These challenges often used randomized HTML5 canvas elements, making them hard to bypass with automation. While Cloudflare Turnstile was once the primary CAPTCHA, Tycoon2FA shifted to using a rotating set of custom CAPTCHA challenges. The CAPTCHA acted as a gate in the flow, legitimizing the process and nudging the target to continue.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig10-custom-captcha-pages.webp\" alt=\"Screenshots of CAPTCHA pages observed on Tycoon2FA domains\" class=\"wp-image-145465 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig10-custom-captcha-pages.webp\"><figcaption class=\"wp-element-caption\">Figure 10. Custom CAPTCHA pages observed on Tycoon2FA domains<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">After the CAPTCHA challenge, the user was shown a dynamically generated sign-in portal that mirrored the targeted service\u2019s branding and authentication flow, most often Microsoft or Gmail. The page might even include company branding to enhance legitimacy. When the user submitted credentials, Tycoon2FA immediately relayed them to the real service, triggering the genuine MFA challenge. The phishing page then displayed the same MFA prompt (for example, number matching or code entry). Once the user completed MFA, the attacker captured the session cookie and gained real-time access without needing further authentication, even if the password was changed later. These pages were created with heavily obfuscated and randomized JavaScript and HTML, designed to evade signature-based detection and other security tools.<\/p>\n<p class=\"wp-block-paragraph\">The phishing kit also disrupted analysis through obfuscation and dynamic code generation, including nonfunctional <em>dead<\/em> code, to defeat consistent fingerprinting. When the campaign infrastructure encountered an unexpected or invalid server response (for example, a geolocation outside the allowed targeting zone), the kit replaced phishing content with a decoy page or a benign redirect to avoid exposing the live credential phishing site.<\/p>\n<p class=\"wp-block-paragraph\">Tycoon2FA further complicated investigation by actively checking for analysis of environments or browser automation and adjusting page behavior if detected. These evasive measures included:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Intercepting user input\n<ul>\n<li>Keystroke monitoring<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Blocking copy\/paste and right click functions<\/li>\n<\/ul>\n<\/li>\n<li class=\"wp-block-list-item\">Detecting or blocking automated inspection\n<ul>\n<li>Automation tools (for example, PhantomJS, Burp Suite)<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Disabling common developer tool shortcuts<\/li>\n<\/ul>\n<\/li>\n<li class=\"wp-block-list-item\">Validating and filtering incoming traffic\n<ul>\n<li>Browser fingerprinting<\/li>\n<\/ul>\n<ul>\n<li>Datacenter IP filtering<\/li>\n<\/ul>\n<ul>\n<li>Geolocation restrictions<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Suspicious user agent profiling<\/li>\n<\/ul>\n<\/li>\n<li class=\"wp-block-list-item\">Increased obfuscation\n<ul>\n<li>Encoded content (Base64, Base91)<\/li>\n<\/ul>\n<ul>\n<li>Fragmented or concatenated strings<\/li>\n<\/ul>\n<ul>\n<li>Invisible Unicode characters<\/li>\n<\/ul>\n<ul>\n<li>Layered URL\/URI encoding<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Dead or nonfunctional script<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">If analysis was suspected at any point, the kit redirected to a legitimate decoy site or threw a 404 error.<\/p>\n<p class=\"wp-block-paragraph\">Complementing these anti-analysis measures, Tycoon2FA used increasingly complex redirect logic. Instead of sending victims directly to the phishing page, it chained multiple intermediate hosts, such as Azure Blob Storage, Firebase, Wix, TikTok, or Google resources, to lend legitimacy to the redirect path. Recent changes combined these redirect chains with encoded Uniform Resource Identifier (URI) strings that obscured full URL paths and landing points, frustrating both static URL extraction and detonation attempts. Stacked together, these tactics made Tycoon2FA a resilient, fast-moving system that evaded both automated and manual detection efforts.<\/p>\n<h3 class=\"wp-block-heading\" id=\"credential-theft-and-account-access\">Credential theft and account access<\/h3>\n<p class=\"wp-block-paragraph\">Captured credentials and session tokens were exfiltrated over encrypted channels, often via Telegram bots. Attackers could then access sensitive data and establish persistence by modifying mailbox rules, registering new authenticator apps, or launching follow-on phishing campaigns from compromised accounts. The following diagram breaks down the AiTM process.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig11-AiTM.webp\" alt=\"Diagram showing adversary in the middle attack chain\" class=\"wp-image-145466 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig11-AiTM.webp\"><figcaption class=\"wp-element-caption\">Figure 11. AiTM authentication process<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Tycoon2FA illustrated the evolution of phishing kits in response to rising enterprise defenses, adapting its lures, infrastructure, and evasion techniques to stay ahead of detection. As organizations increasingly adopt MFA, attackers are shifting to tools that target the authentication process itself instead of attempting to circumvent it. Coupled with affordability, scalability, and ease of use, Tycoon2FA posed a persistent and significant threat to both consumer and enterprise accounts, especially those that rely on MFA as a primary safeguard.<\/p>\n<h2 class=\"wp-block-heading\" id=\"mitigation-and-protection-guidance\">Mitigation and protection guidance<\/h2>\n<p class=\"wp-block-paragraph\">Mitigating threats from phishing actors begins with securing user identity by eliminating traditional credentials and adopting passwordless, phishing-resistant MFA methods such as FIDO2 security keys, Windows Hello for Business, and Microsoft Authenticator passkeys.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Threat Intelligence recommends enforcing phishing-resistant MFA for privileged roles in Microsoft Entra ID to significantly reduce the risk of account compromise. Learn how to <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/conditional-access\/policy-admin-phish-resistant-mfa\">require phishing-resistant MFA for admin roles<\/a> and <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/authentication\/how-to-deploy-phishing-resistant-passwordless-authentication\">plan a passwordless deployment<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Passwordless authentication improves security as well as enhances user experience and reduces IT overhead. Explore Microsoft\u2019s <a href=\"https:\/\/www.microsoft.com\/security\/business\/solutions\/passwordless-authentication\">overview of passwordless authentication<\/a> and <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/authentication\/concept-authentication-strengths\">authentication strength guidance<\/a> to understand how to align your organization\u2019s policies with best practices. For broader strategies on defending against identity-based attacks, refer to Microsoft\u2019s blog on <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2025\/05\/29\/defending-against-evolving-identity-attack-techniques\/\">evolving identity attack techniques<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">If Microsoft Defender alerts indicate suspicious activity or confirmed compromised account or a system, it\u2019s essential to act quickly and thoroughly. The following are recommended remediation steps for each affected identity:<\/p>\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Reset credentials<\/strong> \u2013 Immediately reset the account\u2019s password and revoke any active sessions or tokens. This ensures that any stolen credentials can no longer be used.<\/li>\n<li class=\"wp-block-list-item\"><strong>Re-register or remove MFA devices<\/strong> \u2013 Review users\u2019 MFA devices, specifically those recently added or updated.<\/li>\n<li class=\"wp-block-list-item\"><strong>Revert unauthorized payroll or financial changes<\/strong> \u2013 If the attacker modified payroll or financial configurations, such as direct deposit details, revert them to their original state and notify the appropriate internal teams.<\/li>\n<li class=\"wp-block-list-item\"><strong>Remove malicious inbox rules<\/strong> \u2013 Attackers often create inbox rules to hide their activity or forward sensitive data. Review and delete any suspicious or unauthorized rules.<\/li>\n<li class=\"wp-block-list-item\"><strong>Verify MFA reconfiguration<\/strong> \u2013 Confirm that the user has successfully reconfigured MFA and that the new setup uses secure, phishing-resistant methods.<\/li>\n<\/ol>\n<p class=\"wp-block-paragraph\">To defend against the wide range of phishing threats, Microsoft Threat Intelligence recommends the following mitigation steps:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/recommended-settings-for-eop-and-office365\">Review our recommended settings<\/a> for Exchange Online Protection and Microsoft Defender for Office 365.<\/li>\n<li class=\"wp-block-list-item\">Configure Microsoft Defender for Office 365 to <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/safe-links-about\">recheck links on click.<\/a> Safe Links provides URL scanning and rewriting of inbound email messages in mail flow, and time-of-click verification of URLs and links in email messages, other Microsoft 365 applications such as Teams, and other locations such as SharePoint Online. Safe Links scanning occurs in addition to the regular <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/anti-spam-protection-about\">anti-spam<\/a> and <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/anti-malware-protection-about\">anti-malware<\/a> protection in inbound email messages in Microsoft Exchange Online Protection (EOP). Safe Links scanning can help protect your organization from malicious links used in phishing and other attacks.<\/li>\n<li class=\"wp-block-list-item\">Turn on <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/zero-hour-auto-purge\">Zero-hour auto purge (ZAP<\/a>) in Defender for Office 365 to quarantine sent mail in response to newly-acquired threat intelligence and retroactively neutralize malicious phishing, spam, or malware messages that have already been delivered to mailboxes.<\/li>\n<li class=\"wp-block-list-item\">Turn on <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/safe-links-about?ocid=magicti_ta_learndoc&amp;view=o365-worldwide\">Safe Links<\/a> and <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/safe-attachments-about?ocid=magicti_ta_learndoc&amp;view=o365-worldwide\">Safe Attachments<\/a> in Microsoft Defender for Office 365.<\/li>\n<li class=\"wp-block-list-item\">Enable <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-endpoint\/enable-network-protection\">network protection<\/a> in Microsoft Defender for Endpoint.<\/li>\n<li class=\"wp-block-list-item\">Encourage users to use Microsoft Edge and other web browsers that support <a href=\"https:\/\/learn.microsoft.com\/deployedge\/microsoft-edge-security-smartscreen\">Microsoft Defender SmartScreen<\/a>, which identifies and blocks malicious websites, including phishing sites, scam sites, and sites that host malware.<\/li>\n<li class=\"wp-block-list-item\">Turn on <a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/enable-cloud-protection-microsoft-defender-antivirus\">cloud-delivered protection<\/a> in Microsoft Defender Antivirus or the equivalent for your antivirus product to cover rapidly evolving attack tools and techniques. Cloud-based machine learning protections block a majority of new and unknown variants<\/li>\n<li class=\"wp-block-list-item\">Use the <a href=\"https:\/\/docs.microsoft.com\/microsoft-365\/security\/office-365-security\/attack-simulator\">Attack Simulator<\/a> in Microsoft Defender for Office 365 to run realistic, yet safe, simulated phishing and password attack campaigns. Run spear-phishing (credential harvest) simulations to train end-users against clicking URLs in unsolicited messages and disclosing credentials.<\/li>\n<li class=\"wp-block-list-item\">Configure <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-xdr\/automatic-attack-disruption\">automatic attack disruption<\/a> in Microsoft Defender XDR. Automatic attack disruption is designed to contain attacks in progress, limit the impact on an organization\u2019s assets, and provide more time for security teams to remediate the attack fully.<\/li>\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/entra\/fundamentals\/configure-security\">Configure Microsoft Entra with increased security<\/a>.<\/li>\n<li class=\"wp-block-list-item\">Pilot and deploy <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/authentication\/concept-authentication-methods\">phishing-resistant authentication methods<\/a> for users.<\/li>\n<li class=\"wp-block-list-item\">Implement Entra ID <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/authentication\/concept-authentication-strengths\">Conditional Access authentication strength<\/a> to require phishing-resistant authentication for employees and external users for critical apps.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"microsoft-defender-detections\">Microsoft Defender detections<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/security\/business\/microsoft-defender\">Microsoft Defender<\/a> customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog.<\/p>\n<p class=\"wp-block-paragraph\">Customers with provisioned access can also use <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-xdr\/security-copilot-in-microsoft-365-defender\">Microsoft Security Copilot in Microsoft Defender<\/a> to investigate and respond to incidents, hunt for threats, and protect their organization with relevant threat intelligence.<\/p>\n<p class=\"wp-block-paragraph\">The following alerts might indicate threat activity associated with this threat. These alerts, however, can be triggered by unrelated threat activity and are not monitored in the status cards provided with this report.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"10.220369267421\">\n<tr readability=\"2\">\n<td><strong>Tactic<\/strong>&nbsp;<\/td>\n<td><strong>Observed activity<\/strong>&nbsp;<\/td>\n<td><strong>Microsoft Defender coverage<\/strong>&nbsp;<\/td>\n<\/tr>\n<tr readability=\"9.0752032520325\">\n<td>Initial access<\/td>\n<td>Threat actor gains access to account through phishing<\/td>\n<td readability=\"7.621668099742\"><strong><a href=\"https:\/\/www.microsoft.com\/security\/business\/siem-and-xdr\/microsoft-defender-office-365\">Microsoft Defender for Office 365<\/a><\/strong><br \/>\u2013 A potentially malicious URL click was detected<br \/>\u2013 Email messages containing malicious file removed after delivery<br \/>\u2013 Email messages containing malicious URL removed after delivery<br \/>\u2013 Email messages from a campaign removed after delivery. <br \/>\u2013 Email messages removed after delivery <br \/>\u2013 Email reported by user as malware or phish <br \/>\u2013 A user clicked through to a potentially malicious URL <br \/>\u2013 Suspicious email sending patterns detected<\/p>\n<p><strong><a href=\"https:\/\/www.microsoft.com\/security\/business\/siem-and-xdr\/microsoft-defender-xdr\">Microsoft Defender XDR<\/a><\/strong><br \/>\u2013 User compromised in AiTM phishing attack <br \/>\u2013 Authentication request from AiTM-related phishing page <br \/>\u2013 Risky sign-in after clicking a possible AiTM phishing URL <br \/>\u2013 Successful network connection to IP associated with an AiTM phishing kit <br \/>\u2013 Successful network connection to a known AiTM phishing kit <br \/>\u2013 Suspicious network connection to a known AiTM phishing kit <br \/>\u2013 Possible compromise of user credentials through an AiTM phishing attack <br \/>\u2013 Potential user compromise via AiTM phishing attack <br \/>\u2013 AiTM phishing attack results in user account compromise <br \/>\u2013 Possible AiTM attempt based on suspicious sign-in attributes <br \/>\u2013 User signed in to a known AiTM phishing page<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"4.0350877192982\">\n<td>Defense evasion<\/td>\n<td>Threat actors create an inbox rule post-compromise<\/td>\n<td><strong><a href=\"https:\/\/www.microsoft.com\/security\/business\/siem-and-xdr\/microsoft-defender-cloud-apps\">Microsoft Defender for Cloud Apps<\/a><\/strong><br \/>\u2013 Possible BEC-related inbox rule<br \/>\u2013 Suspicious inbox manipulation rule<\/td>\n<\/tr>\n<tr readability=\"6.8828828828829\">\n<td>Credential access, Collection<\/td>\n<td>Threat actors use AiTM to support follow-on behaviors<\/td>\n<td><strong><a href=\"https:\/\/www.microsoft.com\/security\/business\/endpoint-security\/microsoft-defender-endpoint\">Microsoft Defender for Endpoint<\/a><\/strong> <br \/>\u2013 Suspicious activity likely indicative of a connection to an adversary-in-the-middle (AiTM) phishing site<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Additionally, using Microsoft Defender for Cloud Apps <a href=\"https:\/\/learn.microsoft.com\/defender-cloud-apps\/enable-instant-visibility-protection-and-governance-actions-for-your-apps\">connectors<\/a>, Microsoft Defender XDR raises AiTM-related alerts in multiple scenarios. For Microsoft Entra ID customers using Microsoft Edge, attempts by attackers to replay session cookies to access cloud applications are detected by Microsoft Defender XDR through Defender for Cloud Apps connectors for Microsoft Office 365 and Azure. In such scenarios, Microsoft Defender XDR raises the following alerts:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Stolen session cookie was used<\/li>\n<li class=\"wp-block-list-item\">User compromised through session cookie hijack<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Microsoft Defender XDR raises the following alerts by combining Microsoft Defender for Office 365 <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/safe-links-about\">URL click<\/a> and Microsoft Entra ID Protection <a href=\"https:\/\/learn.microsoft.com\/entra\/id-protection\/howto-identity-protection-investigate-risk\">risky sign-ins<\/a> signal.<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Possible AiTM phishing attempt<\/li>\n<li class=\"wp-block-list-item\">Risky sign-in attempt after clicking a possible AiTM phishing URL<\/li>\n<\/ul>\n<h3 class=\"wp-block-heading\" id=\"microsoft-security-copilot\">Microsoft Security Copilot<\/h3>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-in-microsoft-365-defender\">Microsoft Security Copilot is embedded in Microsoft Defender<\/a> and provides security teams with AI-powered capabilities to summarize incidents, analyze files and scripts, summarize identities, use guided responses, and generate device summaries, hunting queries, and incident reports.<\/p>\n<p class=\"wp-block-paragraph\">Customers can also <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-agents-defender\">deploy AI agents<\/a>, including the following <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/agents-overview\">Microsoft Security Copilot agents<\/a>, to perform security tasks efficiently:<\/p>\n<p class=\"wp-block-paragraph\">Security Copilot is also available as a <a href=\"https:\/\/learn.microsoft.com\/en-us\/copilot\/security\/experiences-security-copilot\">standalone experience<\/a> where customers can perform specific security-related tasks, such as incident investigation, user analysis, and vulnerability impact assessment. In addition, Security Copilot offers <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/developer\/custom-agent-overview\">developer scenarios<\/a> that allow customers to build, test, publish, and integrate AI agents and plugins to meet unique security needs.<\/p>\n<h3 class=\"wp-block-heading\" id=\"threat-intelligence-reports\">Threat intelligence reports<\/h3>\n<p class=\"wp-block-paragraph\">Microsoft Defender XDR customers can use the following <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/threat-analytics\">threat analytics<\/a> reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments:<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Security Copilot customers can also use the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/security-copilot-and-defender-threat-intelligence?bc=%2Fsecurity-copilot%2Fbreadcrumb%2Ftoc.json&amp;toc=%2Fsecurity-copilot%2Ftoc.json#turn-on-the-security-copilot-integration-in-defender-ti\">Microsoft Security Copilot integration<\/a> in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/using-copilot-threat-intelligence-defender-xdr\">embedded experience<\/a> in the Microsoft Defender portal to get more information about this threat actor.<\/p>\n<h3 class=\"wp-block-heading\" id=\"advanced-hunting\">Advanced hunting<\/h3>\n<p class=\"wp-block-paragraph\">Microsoft Defender customers can run the following <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/advanced-hunting-overview\">advanced hunting<\/a> queries to find activity associated with Tycoon2FA.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Suspicious sign-in attempts<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Find identities potentially compromised by AiTM attacks:<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"17\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nAADSignInEventsBeta\n| where Timestamp &gt; ago(7d)\n| where IsManaged != 1\n| where IsCompliant != 1\n\/\/Filtering only for medium and high risk sign-in\n| where RiskLevelDuringSignIn in (50, 100)\n| where ClientAppUsed == \"Browser\"\n| where isempty(DeviceTrustType)\n| where isnotempty(State) or isnotempty(Country) or isnotempty(City)\n| where isnotempty(IPAddress)\n| where isnotempty(AccountObjectId)\n| where isempty(DeviceName)\n| where isempty(AadDeviceId)\n| project Timestamp,IPAddress, AccountObjectId, ApplicationId, SessionId, RiskLevelDuringSignIn, Browser\n<\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\"><strong>Suspicious URL clicks from emails<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Look for any suspicious URL clicks from emails by a user before their risky sign-in:<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"11\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nUrlClickEvents\n| where Timestamp between (start .. end) \/\/Timestamp around time proximity of Risky signin by user\n| where AccountUpn has \"<impacted upn or email address>\" and ActionType has \"ClickAllowed\"\n| project Timestamp,Url,NetworkMessageId\n<\/impacted><\/pre>\n<\/div>\n<h3 class=\"wp-block-heading\" id=\"references\">References<\/h3>\n<h3 class=\"wp-block-heading\" id=\"learn-more\">Learn more<\/h3>\n<p class=\"wp-block-paragraph\">For the latest security research from the Microsoft Threat Intelligence community, check out the <a href=\"https:\/\/aka.ms\/threatintelblog\">Microsoft Threat Intelligence Blog<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To get notified about new publications and to join discussions on social media, follow us on <a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence\">LinkedIn<\/a>, <a href=\"https:\/\/x.com\/MsftSecIntel\">X (formerly Twitter)<\/a>, and <a href=\"https:\/\/bsky.app\/profile\/threatintel.microsoft.com\">Bluesky<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the <a href=\"https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence\">Microsoft Threat Intelligence podcast<\/a>.<\/p>\n<p>READ MORE <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/03\/04\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tycoon2FA has become a leading phishing-as-a-service (PhaaS) platforms, enabling campaigns that reach over 500,000 organizations monthly, prompting Microsoft\u2019s Digital Crimes Unit (DCU) to work with Europol and industry partners to facilitate a disruption of Tycoon2FA\u2019s infrastructure and operations.<br \/>\nThe post Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[],"class_list":["post-60261","post","type-post","status-publish","format-standard","hentry","category-microsoft-secure"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-04T16:04:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"432\" \/>\n\t<meta property=\"og:image:height\" content=\"435\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"18 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale\",\"datePublished\":\"2026-03-04T16:04:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/\"},\"wordCount\":3586,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp\",\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/\",\"name\":\"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp\",\"datePublished\":\"2026-03-04T16:04:24+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp\",\"contentUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/","og_locale":"en_US","og_type":"article","og_title":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-03-04T16:04:24+00:00","og_image":[{"width":432,"height":435,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"18 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale","datePublished":"2026-03-04T16:04:24+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/"},"wordCount":3586,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp","articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/","url":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/","name":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp","datePublished":"2026-03-04T16:04:24+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/#primaryimage","url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp","contentUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/03\/Tycoon2FA-Fig1-volume-of-phishing-messages.webp"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60261","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=60261"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60261\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=60261"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=60261"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=60261"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}