# Storm-1747

> As of 2026-06-16, Storm-1747 is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning phishing. Also known as Tycoon 2FA operators. ATT&CK coverage spans 26 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1056 (Input Capture).

- **Tracked threats:** 2
- **Categories:** PHISHING
- **Also known as:** Tycoon 2FA operators
- **As of:** 2026-06-16

## ATT&CK techniques observed

26 techniques observed across 2 of 2 tracked threats. Tactics: Credential Access (7), Resource Development (3), Stealth (formerly Defense Evasion) (3), Collection (2), Command and Control (2), Lateral Movement (2).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1056](https://intel.threadlinqs.com/technique/T1056) Input Capture — Credential Access — observed in 2 of 2 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 2 of 2 tracked threats
- [T1111](https://intel.threadlinqs.com/technique/T1111) Multi-Factor Authentication Interception — Credential Access — observed in 2 of 2 tracked threats
- [T1187](https://intel.threadlinqs.com/technique/T1187) Forced Authentication — Credential Access — observed in 2 of 2 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 2 of 2 tracked threats
- [T1557](https://intel.threadlinqs.com/technique/T1557) Adversary-in-the-Middle — Credential Access — observed in 2 of 2 tracked threats
- [T1564](https://intel.threadlinqs.com/technique/T1564) Hide Artifacts — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 2 of 2 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 2 of 2 tracked threats
- [T1598](https://intel.threadlinqs.com/technique/T1598) Phishing for Information — Reconnaissance — observed in 2 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 1 of 2 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Persistence — observed in 1 of 2 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 1 of 2 tracked threats

## Tracked threats

- [Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & Gmail](https://intel.threadlinqs.com/threat/TL-2026-0818) — HIGH
- [Tycoon2FA Phishing-as-a-Service Platform Persists Post-Europol Takedown with Rapid Infrastructure Recovery](https://intel.threadlinqs.com/threat/TL-2026-0257) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Storm-1747
