Tycoon2FA Phishing-as-a-Service Platform Persists Post-Europol Takedown with Rapid Infrastructure Recovery — Threadlinqs Intelligence
As of 2026-05-30, Tycoon2FA Phishing-as-a-Service Platform Persists Post-Europol Takedown with Rapid Infrastructure Recovery is a critical-severity phishing threat attributed to Saad Fridi (Pakistan), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-0257 · Severity: CRITICAL · Status: ACTIVE · Category: PHISHING
Attribution: Saad Fridi · Pakistan · FINANCIAL
Tycoon2FA, a subscription-based phishing-as-a-service (PhaaS) platform responsible for 62% of phishing attempts blocked by Microsoft in mid-2025, recovered to pre-disruption activity volumes within 24
Tycoon2FA is a sophisticated phishing-as-a-service platform that has operated since August 2023, providing subscription-based access to adversary-in-the-middle (AITM) phishing infrastructure capable of bypassing multi-factor authentication. The platform was tracked by Microsoft as Storm-1747 and its primary developer is alleged to be Saad Fridi (aliases SaaadFridi, Mr_Xaad), believed to be based in Pakistan.
The platform's core mechanism deploys reverse proxy servers that host deceptive login pages mimicking Microsoft 365, Google Workspace, SharePoint, OneDrive, and Outlook authentication interfaces. When victims interact with these pages, Tycoon2FA relays credentials and MFA codes to the legitimate authentication service in real-time while capturing session cookies. These stolen session cookies allow attackers to replay authenticated sessions, effectively bypassing MFA protections including SMS codes, one-time passcodes, and push notifications. Critically, session cookies remain valid even if the victim subsequently changes their password, unless active sessions are explicitly revoked.
By mid-2025, Tycoon2FA had become the most prolific PhaaS platform observed by Microsoft, accounting for approximately 62% of all blocked phishing attempts. The platform generated over 30 million malicious emails monthly, reaching more than 500,000 organizations worldwide. Nearly 100,000 organizations were compromised globally, including schools, hospitals, and public institutions. The service maintained approximately 2,000 registered operators who accessed the platform through Telegram and Signal channels, with pricing starting at $120 for 10-day access or $350 for monthly web-based administration panel access.
On March 4, 2026, a Europol-coordinated operation involving law enforcement from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom—supported by private sector partners Microsoft, Cloudflare, Intel 471, Proofpoint, Trend Micro, SpyCloud, Coinbase, and Shadowserver Foundation—dismantled 330 domains forming the core infrastructure. However, CrowdStrike's analysis published March 20, 2026 revealed the platform demonstrated remarkable operational resilience: after a temporary 75% reduction in daily campaign volume lasting approximately 24 hours, Tycoon2FA operators restored operations to pre-disruption levels by March 5-6, 2026.
Post-takedown, CrowdStrike observed at least 30 suspected incidents across 12+ credential-capture pages within 48 hours. The platform's infrastructure relies heavily on IPv6 addresses owned by Romania-based ISP M247 Europe SRL for automated login operations, and operators continued procuring new IPv6 addresses at pre-disruption rates. Domain registration patterns showed both newly registered domains (June 2025-February 2026 vintage) and compromised legitimate third-party domains (pre-2012 registrations) being used for redirect chains.
The platform employs multiple evasion techniques including AI-generated decoy webpages, geofencing measures (returning decoy pages when geofencing fails), custom CAPTCHA algorithms (replacing earlier Cloudflare Turnstile usage), obfuscated JavaScript for credential proxying, browser fingerprinting, anti-bot screening, and keystroke monitoring. A variant called Salty2FA was also observed leveraging Cloudflare r2.dev and workers.dev shared infrastructure.
Post-compromise activities typically include business email compromise (BEC), creation of suspicious inbox rules to conceal attacker activity, internal spearphishing using compromised accounts (ATO Jumping technique), data exfiltration, and credential resale. Compromised accounts serve as initial access vectors for ransomware deployment. SpyCloud analysis of exposed panels revealed 328,865 victim records containing 173,000+ unique email addresses, 67,000 usernames, and 264,000 passwords. Geographic analysis of non-obfuscated operator logins showed highest concentrations from Nigeria (211 logins) and South Africa (6
Weaknesses (CWE)
CWE-294, CWE-384, CWE-346
Target sectors: government, education, healthcare, financial, technology, manufacturing, retail, energy, telecommunications, legal
Target regions: North America, Europe, Asia Pacific, United Kingdom, India, Canada, France, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, CRITICAL, threat intelligence, cybersecurity, T1598, T1598, T1583, T1583, T1584, T1608, T1566, T1204, T1078, T1036