Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-05

Tycoon 2FA operators

Also known as:Tycoon2FATycoon 2FA PhaaS

As of 2026-08-04, Tycoon 2FA operators is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning threat intel, phishing. Also known as Tycoon2FA, Tycoon 2FA PhaaS. ATT&CK coverage spans 46 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1056 (Input Capture).

Tracked threats
33 high
First seen
2026-05-17
Last seen
2026-08-04
ATT&CK techniques
46across 3 of 3 threats
Related CVEs
0None referenced
3 tracked threat(s) · Categories: THREAT_INTEL, PHISHING

Activity timeline

Tycoon 2FA operators appears in 3 tracked threats between and ; the busiest month was 2026-05 with 1 report.

ATT&CK techniques observed

46 techniques observed across 3 of 3 tracked threats · Credential Access (10), Stealth (formerly Defense Evasion) (6), Command and Control (5), Initial Access (5), Resource Development (5), Collection (4)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1056 Input Capture — Credential Accessobserved in 2 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 3 tracked threats
  • T1204 User Execution — Executionobserved in 2 of 3 tracked threats
  • T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 2 of 3 tracked threats
  • T1557 Adversary-in-the-Middle — Credential Accessobserved in 2 of 3 tracked threats
  • T1566 Phishing — Initial Accessobserved in 2 of 3 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 2 of 3 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 2 of 3 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 1 of 3 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 1 of 3 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 1 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 1 of 3 tracked threats

Tracked threats