Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & Gmail
Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (TL-2026-0818), also tracked as Tycoon 2FA, is a high-severity phishing campaign, first published 2026-06-16. It is attributed to Storm-1747 with medium confidence, affects Microsoft Microsoft 365 / Entra ID / Outlook / SharePoint / OneDrive, maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0818
- Threat ID
- TL-2026-0818
- Also known as
- Tycoon 2FA, Tycoon2FA
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-06-16
- Last reviewed
- 2026-06-16
- Attribution
- Storm-1747
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- education, healthcare, financial, non-profit, government
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service
Malware and tooling: Tycoon 2FA, Tycoon 2FA reverse-proxy AiTM relay, javascript-obfuscator
Tycoon 2FA is a widely deployed Adversary-in-the-Middle (AiTM) Phishing-as-a-Service platform operated by Storm-1747 that uses reverse-proxy relays to capture credentials, relay MFA challenges, and steal authenticated session cookies for Microsoft 365 and Gmail, enabling full account takeover that survives password resets. At its peak it accounted for roughly 62% of phishing attempts blocked by Microsoft and reached over 500,000 organizations per month before a March 2026 Microsoft/Europol-led disruption.
How Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service works
Tycoon 2FA is a Phishing-as-a-Service (PhaaS) platform first observed by Sekoia in October 2023 (active since August 2023) and attributed by Microsoft Threat Intelligence to the actor tracked as Storm-1747, with documented infrastructure and tooling overlaps to the Dadsec/Saint operation. The kit defeats multi-factor authentication using an Adversary-in-the-Middle (AiTM) reverse-proxy architecture: a victim is lured to a spoofed Microsoft 365, Outlook, SharePoint, OneDrive, or Gmail sign-in portal that transparently relays the victim's username, password, and MFA response to the legitimate service while intercepting the resulting authenticated session cookie. Because the attacker captures the live session token, the resulting account access bypasses SMS codes, one-time passcodes, and push-notification MFA and persists even if the victim later changes their password.
Delivery uses email lures in four observed forms: PDF/DOC/DOCX attachments containing QR codes, SVG files with embedded redirect logic, HTML attachments with short messages, and direct redirect links appearing to originate from trusted services. Victims are funneled through multi-layer redirect chains abusing legitimate intermediaries (Azure Blob Storage, Firebase, Wix, TikTok) and Cloudflare-hosted domains, including Cloudflare Workers URLs used for automated subdomain rotation. Early versions gated traffic behind a Cloudflare Turnstile challenge; later versions shifted to a custom CAPTCHA built from randomized HTML5 canvas elements. The kit performs aggressive cloaking and anti-analysis: datacenter-IP and Tor filtering, geolocation restrictions, user-agent profiling, browser fingerprinting, dead-code injection, Base64/Base91 and invisible-Unicode obfuscation (built with the public 'javascript-obfuscator' tool), keystroke monitoring, and copy/paste, right-click, and developer-tool blocking. Captured data — email, password, 2FA code, IP, user-agent, session ID, and fingerprint — is exfiltrated over a Socket.IO WebSocket channel and forwarded to operators via Telegram bots. Access is sold on Telegram at roughly $120 for 10-day and $350 for 30-day panel access.
Despite a coordinated March 2026 takedown led by the Microsoft Digital Crimes Unit and Europol that seized over 300 domains, operators adapted within weeks, rotating to short-lived (24-72 hour) FQDNs and shifting subdomain naming from high-entropy strings to readable, benign-looking terms. Organizations should treat Tycoon 2FA as an ongoing identity-compromise threat and prioritize phishing-resistant MFA, session-token protection, and AiTM-aware detection.
MITRE ATT&CK techniques used in TL-2026-0818
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1564 Hide Artifacts
Credential Access
T1056 Input Capture; T1110 Brute Force; T1111 Multi-Factor Authentication Interception; T1187 Forced Authentication; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Command and Control
T1071 Application Layer Protocol
Collection
Persistence
T1137 Office Application Startup
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Reconnaissance
Affected products and versions in Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service
- Microsoft — Microsoft 365 / Entra ID / Outlook / SharePoint / OneDrive
Vulnerable versions: accounts protected by SMS, OTP, or push-notification MFA
Fixed in: accounts using phishing-resistant FIDO2/WebAuthn or certificate-based auth - Google — Gmail / Google Workspace
Vulnerable versions: accounts protected by SMS, OTP, or push-notification MFA
Fixed in: accounts using phishing-resistant passkeys / security keys
Remediation for Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service
Immediate actions
- Enforce phishing-resistant MFA (FIDO2/WebAuthn passkeys or certificate-based auth) which defeats AiTM credential/token relay
- Revoke active sessions and rotate credentials for any user who interacted with a suspected Tycoon 2FA lure
- Block known Tycoon 2FA domains/TLD patterns and short-lived FQDNs at the web proxy and DNS layer
Workarounds
- Strip or sandbox QR codes, SVG, and HTML attachments at the secure email gateway
- Restrict OAuth/session token lifetimes and require reauthentication for sensitive operations
Longer-term hardening
- Deploy continuous-access-evaluation and conditional-access policies that bind sessions to compliant/managed devices and known networks
- Enable token-protection / token-binding so stolen session cookies cannot be replayed from attacker infrastructure
- Deploy AiTM-aware email and identity detection (impossible-travel, anomalous session cookie reuse, new-device sign-ins)
Weaknesses (CWE) in Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service
CWE-287, CWE-294, CWE-1390
Timeline of Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service
- Tycoon 2FA admin panel domain tycoongroup.ws first observed (per Sekoia).
- Tycoon 2FA PhaaS platform becomes active and is advertised on Telegram.
- Sekoia identifies Tycoon 2FA and documents widespread AiTM adoption.
- New Tycoon 2FA version with enhanced obfuscation, anti-detection, and altered traffic patterns first observed.
- Active campaign samples observed using .ru/.es phishing FQDNs with per-victim email path encoding.
- Peak-volume period begins; kit reaches over 500,000 organizations per month worldwide (Oct 2025-Jan 2026).
- Infrastructure pattern shift: subdomains move from high-entropy strings to readable benign terms (cloud, desktop, azure).
- Microsoft observes more than three million messages associated with Tycoon 2FA activity in a single month.
- Microsoft DCU and Europol announce coordinated disruption seizing 300+ domains; operators adapt within weeks.
Sources cited for Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service
- Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
- Tycoon 2FA: an in-depth analysis of the latest version of the AiTM phishing kit
- Tycoon 2FA: Phishing Kit Being Used to Bypass MFA
- PhaaS the Secrets: The Hidden Ties Between Tycoon2FA and Dadsec's Operations
- Tycoon 2FA AiTM detection for Entra ID and Google
- New Tycoon 2FA Phishing Kit Raises Cybersecurity Concerns
- Top 5 Phishing Domain Takedown Services (originating source feed)
Threats related to Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams Vishing (STAC4749), and Lumma Stealer Converge on the Legal Sector
- Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra Sessions
- EvilTokens/ARToken Device-Code Phishing Kit Bypasses MFA to Compromise Microsoft 365 Accounts
- Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials and Session Tokens
Detection coverage for TL-2026-0818
As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0818 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.