Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & Gmail — Threadlinqs Intelligence
As of 2026-06-16, Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & Gmail is a high-severity phishing threat attributed to Storm-1747, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0818 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Storm-1747 · FINANCIAL
Tycoon 2FA is a widely deployed Adversary-in-the-Middle (AiTM) Phishing-as-a-Service platform operated by Storm-1747 that uses reverse-proxy relays to capture credentials, relay MFA challenges, and
Tycoon 2FA is a Phishing-as-a-Service (PhaaS) platform first observed by Sekoia in October 2023 (active since August 2023) and attributed by Microsoft Threat Intelligence to the actor tracked as Storm-1747, with documented infrastructure and tooling overlaps to the Dadsec/Saint operation. The kit defeats multi-factor authentication using an Adversary-in-the-Middle (AiTM) reverse-proxy architecture: a victim is lured to a spoofed Microsoft 365, Outlook, SharePoint, OneDrive, or Gmail sign-in portal that transparently relays the victim's username, password, and MFA response to the legitimate service while intercepting the resulting authenticated session cookie. Because the attacker captures the live session token, the resulting account access bypasses SMS codes, one-time passcodes, and push-notification MFA and persists even if the victim later changes their password.
Delivery uses email lures in four observed forms: PDF/DOC/DOCX attachments containing QR codes, SVG files with embedded redirect logic, HTML attachments with short messages, and direct redirect links appearing to originate from trusted services. Victims are funneled through multi-layer redirect chains abusing legitimate intermediaries (Azure Blob Storage, Firebase, Wix, TikTok) and Cloudflare-hosted domains, including Cloudflare Workers URLs used for automated subdomain rotation. Early versions gated traffic behind a Cloudflare Turnstile challenge; later versions shifted to a custom CAPTCHA built from randomized HTML5 canvas elements. The kit performs aggressive cloaking and anti-analysis: datacenter-IP and Tor filtering, geolocation restrictions, user-agent profiling, browser fingerprinting, dead-code injection, Base64/Base91 and invisible-Unicode obfuscation (built with the public 'javascript-obfuscator' tool), keystroke monitoring, and copy/paste, right-click, and developer-tool blocking. Captured data — email, password, 2FA code, IP, user-agent, session ID, and fingerprint — is exfiltrated over a Socket.IO WebSocket channel and forwarded to operators via Telegram bots. Access is sold on Telegram at roughly $120 for 10-day and $350 for 30-day panel access.
Despite a coordinated March 2026 takedown led by the Microsoft Digital Crimes Unit and Europol that seized over 300 domains, operators adapted within weeks, rotating to short-lived (24-72 hour) FQDNs and shifting subdomain naming from high-entropy strings to readable, benign-looking terms. Organizations should treat Tycoon 2FA as an ongoing identity-compromise threat and prioritize phishing-resistant MFA, session-token protection, and AiTM-aware detection.
Weaknesses (CWE)
CWE-287, CWE-294, CWE-1390
Target sectors: education, healthcare, financial, non-profit, government
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1598, T1566, T1566, T1557, T1056, T1111, T1539, T1187, T1110, T1036