Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & Gmail

Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (TL-2026-0818), also tracked as Tycoon 2FA, is a high-severity phishing campaign, first published 2026-06-16. It is attributed to Storm-1747 with medium confidence, affects Microsoft Microsoft 365 / Entra ID / Outlook / SharePoint / OneDrive, maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-0818

Threat ID
TL-2026-0818
Also known as
Tycoon 2FA, Tycoon2FA
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-06-16
Last reviewed
2026-06-16
Attribution
Storm-1747
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
education, healthcare, financial, non-profit, government
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
22

Malware and tooling in Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service

Malware and tooling: Tycoon 2FA, Tycoon 2FA reverse-proxy AiTM relay, javascript-obfuscator

Tycoon 2FA is a widely deployed Adversary-in-the-Middle (AiTM) Phishing-as-a-Service platform operated by Storm-1747 that uses reverse-proxy relays to capture credentials, relay MFA challenges, and steal authenticated session cookies for Microsoft 365 and Gmail, enabling full account takeover that survives password resets. At its peak it accounted for roughly 62% of phishing attempts blocked by Microsoft and reached over 500,000 organizations per month before a March 2026 Microsoft/Europol-led disruption.

How Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service works

Tycoon 2FA is a Phishing-as-a-Service (PhaaS) platform first observed by Sekoia in October 2023 (active since August 2023) and attributed by Microsoft Threat Intelligence to the actor tracked as Storm-1747, with documented infrastructure and tooling overlaps to the Dadsec/Saint operation. The kit defeats multi-factor authentication using an Adversary-in-the-Middle (AiTM) reverse-proxy architecture: a victim is lured to a spoofed Microsoft 365, Outlook, SharePoint, OneDrive, or Gmail sign-in portal that transparently relays the victim's username, password, and MFA response to the legitimate service while intercepting the resulting authenticated session cookie. Because the attacker captures the live session token, the resulting account access bypasses SMS codes, one-time passcodes, and push-notification MFA and persists even if the victim later changes their password.

Delivery uses email lures in four observed forms: PDF/DOC/DOCX attachments containing QR codes, SVG files with embedded redirect logic, HTML attachments with short messages, and direct redirect links appearing to originate from trusted services. Victims are funneled through multi-layer redirect chains abusing legitimate intermediaries (Azure Blob Storage, Firebase, Wix, TikTok) and Cloudflare-hosted domains, including Cloudflare Workers URLs used for automated subdomain rotation. Early versions gated traffic behind a Cloudflare Turnstile challenge; later versions shifted to a custom CAPTCHA built from randomized HTML5 canvas elements. The kit performs aggressive cloaking and anti-analysis: datacenter-IP and Tor filtering, geolocation restrictions, user-agent profiling, browser fingerprinting, dead-code injection, Base64/Base91 and invisible-Unicode obfuscation (built with the public 'javascript-obfuscator' tool), keystroke monitoring, and copy/paste, right-click, and developer-tool blocking. Captured data — email, password, 2FA code, IP, user-agent, session ID, and fingerprint — is exfiltrated over a Socket.IO WebSocket channel and forwarded to operators via Telegram bots. Access is sold on Telegram at roughly $120 for 10-day and $350 for 30-day panel access.

Despite a coordinated March 2026 takedown led by the Microsoft Digital Crimes Unit and Europol that seized over 300 domains, operators adapted within weeks, rotating to short-lived (24-72 hour) FQDNs and shifting subdomain naming from high-entropy strings to readable, benign-looking terms. Organizations should treat Tycoon 2FA as an ongoing identity-compromise threat and prioritize phishing-resistant MFA, session-token protection, and AiTM-aware detection.

MITRE ATT&CK techniques used in TL-2026-0818

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1564 Hide Artifacts

Credential Access

T1056 Input Capture; T1110 Brute Force; T1111 Multi-Factor Authentication Interception; T1187 Forced Authentication; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Command and Control

T1071 Application Layer Protocol

Collection

T1115 Clipboard Data

Persistence

T1137 Office Application Startup

Initial Access

T1566 Phishing

Exfiltration

T1567 Exfiltration Over Web Service

Reconnaissance

T1598 Phishing for Information

Affected products and versions in Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service

  • Microsoft — Microsoft 365 / Entra ID / Outlook / SharePoint / OneDrive
    Vulnerable versions: accounts protected by SMS, OTP, or push-notification MFA
    Fixed in: accounts using phishing-resistant FIDO2/WebAuthn or certificate-based auth
  • Google — Gmail / Google Workspace
    Vulnerable versions: accounts protected by SMS, OTP, or push-notification MFA
    Fixed in: accounts using phishing-resistant passkeys / security keys

Remediation for Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service

Immediate actions

  • Enforce phishing-resistant MFA (FIDO2/WebAuthn passkeys or certificate-based auth) which defeats AiTM credential/token relay
  • Revoke active sessions and rotate credentials for any user who interacted with a suspected Tycoon 2FA lure
  • Block known Tycoon 2FA domains/TLD patterns and short-lived FQDNs at the web proxy and DNS layer

Workarounds

  • Strip or sandbox QR codes, SVG, and HTML attachments at the secure email gateway
  • Restrict OAuth/session token lifetimes and require reauthentication for sensitive operations

Longer-term hardening

  • Deploy continuous-access-evaluation and conditional-access policies that bind sessions to compliant/managed devices and known networks
  • Enable token-protection / token-binding so stolen session cookies cannot be replayed from attacker infrastructure
  • Deploy AiTM-aware email and identity detection (impossible-travel, anomalous session cookie reuse, new-device sign-ins)

Weaknesses (CWE) in Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service

CWE-287, CWE-294, CWE-1390

Timeline of Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service

  • Tycoon 2FA admin panel domain tycoongroup.ws first observed (per Sekoia).
  • Tycoon 2FA PhaaS platform becomes active and is advertised on Telegram.
  • Sekoia identifies Tycoon 2FA and documents widespread AiTM adoption.
  • New Tycoon 2FA version with enhanced obfuscation, anti-detection, and altered traffic patterns first observed.
  • Active campaign samples observed using .ru/.es phishing FQDNs with per-victim email path encoding.
  • Peak-volume period begins; kit reaches over 500,000 organizations per month worldwide (Oct 2025-Jan 2026).
  • Infrastructure pattern shift: subdomains move from high-entropy strings to readable benign terms (cloud, desktop, azure).
  • Microsoft observes more than three million messages associated with Tycoon 2FA activity in a single month.
  • Microsoft DCU and Europol announce coordinated disruption seizing 300+ domains; operators adapt within weeks.

Sources cited for Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service

Threats related to Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service

Detection coverage for TL-2026-0818

As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0818 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats