Tycoon2FA Phishing-as-a-Service Platform Persists Post-Europol Takedown with Rapid Infrastructure Recovery

Tycoon2FA Phishing-as-a-Service Platform Persists (TL-2026-0257), also tracked as Tycoon 2FA, is a critical-severity phishing campaign, first published 2026-03-20. It is attributed to Saad Fridi (Pakistan) with high confidence, affects Microsoft Microsoft 365, maps to 23 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-0257

Threat ID
TL-2026-0257
Also known as
Tycoon 2FA, Tycoon2FA PhaaS, Storm-1747 Operations
Severity
CRITICAL
Status
ACTIVE
Category
PHISHING
First published
2026-03-20
Last reviewed
2026-03-20
Attribution
Saad Fridi
Attribution confidence
HIGH
Nation-state nexus
Pakistan
Motivation
FINANCIAL
Target sectors
government, education, healthcare, financial, technology, manufacturing, retail, energy, telecommunications, legal
Target regions
North America, Europe, Asia Pacific, United Kingdom, India, Canada, France, Global
Detection rules
9
Indicators of compromise
29

Malware and tooling in Tycoon2FA Phishing-as-a-Service Platform Persists

Malware and tooling: Salty2FA, Tycoon2FA

Tycoon2FA, a subscription-based phishing-as-a-service (PhaaS) platform responsible for 62% of phishing attempts blocked by Microsoft in mid-2025, recovered to pre-disruption activity volumes within 24 hours of Europol's March 4, 2026 takedown of 330 domains. The platform uses adversary-in-the-middle (AITM) techniques to steal session cookies and compromise enterprise Microsoft 365 and Google Workspace accounts, enabling business email compromise at scale with over 30 million malicious emails generated monthly.

How Tycoon2FA Phishing-as-a-Service Platform Persists works

Tycoon2FA is a sophisticated phishing-as-a-service platform that has operated since August 2023, providing subscription-based access to adversary-in-the-middle (AITM) phishing infrastructure capable of bypassing multi-factor authentication. The platform was tracked by Microsoft as Storm-1747 and its primary developer is alleged to be Saad Fridi (aliases SaaadFridi, Mr_Xaad), believed to be based in Pakistan.

The platform's core mechanism deploys reverse proxy servers that host deceptive login pages mimicking Microsoft 365, Google Workspace, SharePoint, OneDrive, and Outlook authentication interfaces. When victims interact with these pages, Tycoon2FA relays credentials and MFA codes to the legitimate authentication service in real-time while capturing session cookies. These stolen session cookies allow attackers to replay authenticated sessions, effectively bypassing MFA protections including SMS codes, one-time passcodes, and push notifications. Critically, session cookies remain valid even if the victim subsequently changes their password, unless active sessions are explicitly revoked.

By mid-2025, Tycoon2FA had become the most prolific PhaaS platform observed by Microsoft, accounting for approximately 62% of all blocked phishing attempts. The platform generated over 30 million malicious emails monthly, reaching more than 500,000 organizations worldwide. Nearly 100,000 organizations were compromised globally, including schools, hospitals, and public institutions. The service maintained approximately 2,000 registered operators who accessed the platform through Telegram and Signal channels, with pricing starting at $120 for 10-day access or $350 for monthly web-based administration panel access.

On March 4, 2026, a Europol-coordinated operation involving law enforcement from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom—supported by private sector partners Microsoft, Cloudflare, Intel 471, Proofpoint, Trend Micro, SpyCloud, Coinbase, and Shadowserver Foundation—dismantled 330 domains forming the core infrastructure. However, CrowdStrike's analysis published March 20, 2026 revealed the platform demonstrated remarkable operational resilience: after a temporary 75% reduction in daily campaign volume lasting approximately 24 hours, Tycoon2FA operators restored operations to pre-disruption levels by March 5-6, 2026.

Post-takedown, CrowdStrike observed at least 30 suspected incidents across 12+ credential-capture pages within 48 hours. The platform's infrastructure relies heavily on IPv6 addresses owned by Romania-based ISP M247 Europe SRL for automated login operations, and operators continued procuring new IPv6 addresses at pre-disruption rates. Domain registration patterns showed both newly registered domains (June 2025-February 2026 vintage) and compromised legitimate third-party domains (pre-2012 registrations) being used for redirect chains.

The platform employs multiple evasion techniques including AI-generated decoy webpages, geofencing measures (returning decoy pages when geofencing fails), custom CAPTCHA algorithms (replacing earlier Cloudflare Turnstile usage), obfuscated JavaScript for credential proxying, browser fingerprinting, anti-bot screening, and keystroke monitoring. A variant called Salty2FA was also observed leveraging Cloudflare r2.dev and workers.dev shared infrastructure.

Post-compromise activities typically include business email compromise (BEC), creation of suspicious inbox rules to conceal attacker activity, internal spearphishing using compromised accounts (ATO Jumping technique), data exfiltration, and credential resale. Compromised accounts serve as initial access vectors for ransomware deployment. SpyCloud analysis of exposed panels revealed 328,865 victim records containing 173,000+ unique email addresses, 67,000 usernames, and 264,000 passwords. Geographic analysis of non-obfuscated operator logins showed highest concentrations from Nigeria (211 logins) and South Africa (62 logins).

MITRE ATT&CK techniques used in TL-2026-0257

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1078 Valid Accounts; T1550 Use Alternate Authentication Material; T1564 Hide Artifacts

collection

T1056 Input Capture; T1114 Email Collection

command-and-control

T1102 Web Service

credential-access

T1110 Brute Force; T1111 Multi-Factor Authentication Interception; T1187 Forced Authentication; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

execution

T1204 User Execution

lateral-movement

T1534 Internal Spearphishing

initial-access

T1566 Phishing

exfiltration

T1567 Exfiltration Over Web Service

resource-development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1608 Stage Capabilities

reconnaissance

T1598 Phishing for Information

impact

T1657 Financial Theft

Affected products and versions in Tycoon2FA Phishing-as-a-Service Platform Persists

  • Microsoft — Microsoft 365
    Vulnerable versions: All versions with non-phishing-resistant MFA
    Fixed in: N/A — requires phishing-resistant MFA (FIDO2/WebAuthn)
  • Microsoft — Microsoft Entra ID (Azure AD)
    Vulnerable versions: All versions using SMS/OTP/push MFA
    Fixed in: N/A — requires token protection and FIDO2
  • Microsoft — SharePoint Online
    Vulnerable versions: All cloud versions
    Fixed in: N/A — mitigated via phishing-resistant MFA
  • Microsoft — Outlook / Exchange Online
    Vulnerable versions: All cloud versions
    Fixed in: N/A — mitigated via conditional access
  • Google — Google Workspace
    Vulnerable versions: All versions with non-phishing-resistant MFA
    Fixed in: N/A — requires passkeys/FIDO2

Remediation for Tycoon2FA Phishing-as-a-Service Platform Persists

Immediate actions

  • Block all identified Tycoon2FA phishing domains at DNS and web proxy level
  • Block IPv6 ranges associated with M247 Europe SRL automated logins (2a0d:5600:8::/48)
  • Revoke all active Microsoft 365 and Google Workspace sessions for compromised accounts
  • Reset credentials and MFA tokens for any accounts that interacted with identified phishing pages
  • Review and remove suspicious inbox rules created on compromised accounts
  • Enable conditional access policies requiring compliant devices for cloud authentication

Workarounds

  • Restrict cloud authentication to managed devices only via conditional access
  • Disable legacy authentication protocols that bypass MFA
  • Monitor for OAuth token usage from unexpected IPv6 ranges
  • Implement real-time alerting on new inbox rule creation and email forwarding changes

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware keys) to eliminate AITM session cookie theft
  • Implement continuous access evaluation (CAE) to detect and revoke compromised sessions in real-time
  • Deploy advanced email security with AITM phishing detection capabilities
  • Enable token binding or token protection policies in Microsoft Entra ID
  • Implement browser-based conditional access requiring managed/compliant devices
  • Deploy DNS security solutions with real-time phishing domain intelligence feeds
  • Train users to recognize AITM phishing patterns including fake CAPTCHA pages

Weaknesses (CWE) in Tycoon2FA Phishing-as-a-Service Platform Persists

CWE-294, CWE-384, CWE-346

Timeline of Tycoon2FA Phishing-as-a-Service Platform Persists

  • Tycoon2FA phishing-as-a-service platform first emerged and began offering subscription-based AITM phishing kit access
  • Sekoia published in-depth technical analysis of the latest Tycoon2FA version revealing updated AITM capabilities and custom CAPTCHA implementation
  • Tycoon2FA responsible for 62% of all phishing attempts blocked by Microsoft; generating over 30 million malicious emails per month reaching 500,000+ organizations
  • Europol disrupted RaccoonO365 phishing platform (primary Tycoon2FA competitor), likely increasing Tycoon2FA market share
  • Microsoft blocked over 13 million Tycoon2FA-associated phishing emails in a single month; platform user base reached approximately 2,000 operators
  • Proofpoint observed over 3 million Tycoon2FA-associated phishing messages in February 2026; operators continued domain registration at sustained pace
  • Immediate 75% reduction in daily Tycoon2FA campaign volume following domain seizures; temporary disruption of phishing infrastructure
  • Europol-coordinated operation involving 6 countries (Latvia, Lithuania, Portugal, Poland, Spain, UK) and 8 private sector partners dismantled 330 Tycoon2FA domains including phishing pages and control panels
  • Tycoon2FA campaign volume recovered to pre-disruption levels within approximately 24 hours; operators resumed new domain registration and IPv6 address procurement at pre-takedown rates
  • CrowdStrike documented at least 30 suspected Tycoon2FA incidents across 12+ credential-capture pages within 48 hours of takedown; automated logins from M247 Europe SRL IPv6 addresses continued unchanged
  • CrowdStrike published analysis confirming Tycoon2FA platform fully operational with new domain registrations, IPv6 procurement, and campaign volumes matching pre-disruption levels
  • As of 2026-05-29, Tycoon2FA remains ACTIVE: the March 4 Europol/Microsoft takedown (a civil TRO, not an arrest of operator Saad Fridi/Storm-1747) cut volume only ~24-48h before full recovery. eSentire, BleepingComputer and KnowBe4 (Apr-May 2026) confirm the kit operating and evolving (OAuth device-code phishing, Alibaba Cloud), no CVE, no successor.

Sources cited for Tycoon2FA Phishing-as-a-Service Platform Persists

Threats related to Tycoon2FA Phishing-as-a-Service Platform Persists

Detection coverage for TL-2026-0257

As of 2026-03-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0257 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats