AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams Vishing (STAC4749), and Lumma Stealer Converge on the Legal Sector — Threadlinqs Intelligence
As of 2026-07-30, AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams Vishing (STAC4749), and Lumma Stealer Converge on the Legal Sector is a high-severity phishing threat attributed to Multiple PhaaS, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-1777 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Multiple PhaaS · FINANCIAL
eSentire's Threat Response Unit reports Adversary-in-the-Middle (AiTM) phishing now accounts for 28.57% of initial access events against legal-sector organizations, driven primarily by the Tycoon2FA
Legal-sector organizations experienced a 20% year-over-year rise in security incidents in 2025-2026, with credential- and identity-focused activity (account compromise plus direct credential phishing) comprising 56.3% of all observed threats, per eSentire TRU's Legal Services Threat Intelligence Spotlight. The dominant driver is Adversary-in-the-Middle (AiTM) phishing, which reverse-proxies the real authentication flow of Microsoft 365, Outlook, SharePoint, OneDrive, and Gmail so that a victim who enters correct credentials and completes an MFA challenge still hands the attacker a valid, replayable session cookie -- fully defeating password + OTP/push MFA without touching the identity provider itself.
The leading AiTM engine is Tycoon2FA, a subscription phishing-as-a-service (PhaaS) platform sold via Telegram and Signal ($120/10 days or $350/month for a web admin panel) that has been active since August 2023 and, at its peak, accounted for roughly 62% of all phishing attempts blocked by Microsoft. Tycoon2FA operates a six-stage flow: a Cloudflare Turnstile CAPTCHA gate ('this page is running browser checks to ensure your security'), regex-based victim-email extraction, a redirection page with heavily obfuscated JavaScript (javascript-obfuscator hex-renamed variables, base64/base91 encoding, dead-code injection, invisible Unicode), a spoofed Microsoft/Google/DocuSign/Adobe login page, real-time relay of push/OTP/phone MFA challenges to the legitimate service via a reverse proxy, and final capture of the resulting session cookie over a socket.io WebSocket channel, with stolen data forwarded through Telegram bot channels. Infrastructure rotates rapidly -- FQDNs live only 24-72 hours, are increasingly hosted behind Cloudflare, and use low-verification generic TLDs (.space, .email, .solutions, .live, .today, .calendar) after early campaigns leaned on .es/.ru. Anti-analysis controls filter datacenter and Tor-exit IPs, bot user agents, and automation tooling (PhantomJS, Burp Suite, dev-tools detection). On March 4, 2026, Europol, Microsoft's Digital Crimes Unit, and industry partners (Cloudflare, Coinbase, eSentire, Intel 471, Proofpoint, SpyCloud, Trend Micro, Health-ISAC, Shadowserver, Resecurity, Crowell) seized 330 domains tied to Tycoon2FA's core infrastructure, following prior disruptions of the Caffeine and RaccoonO365 phishing supply chains; by April 2026, Barracuda reported the operators had 'scattered' rather than folded, redistributing across a more fragmented AiTM-kit ecosystem alongside competing PhaaS brands Sneaky2FA and FlowerStorm.
A second major legal-sector vector is ClickFix, a social-engineering technique (not a single malware family) reaching 13.39% of legal incidents versus an 8.77% cross-industry average. Fake browser-error or CAPTCHA pages -- themed as a document viewer, e-filing system, or court-portal notice -- instruct the victim to press Win+R and paste a clipboard string that is actually a PowerShell command, or (in an mshta.exe-based variant) fetch and execute a remote HTML application. A February 2026 Microsoft disclosure documented a DNS-based evolution where the pasted command runs nslookup against an attacker-controlled DNS server and executes the payload returned in the response's Name: field, bypassing URL-based blocking entirely. ClickFix campaigns targeting the legal sector primarily deliver NetSupportManager RAT (26.2% of all legal-sector malware detections), a legitimate dual-use remote-administration tool abused as a RAT: it drops client32.exe alongside a client32.ini configuration file containing a C2 gateway address and encrypted Global Security Key, uses the network User-Agent 'NetSupport Manager/1.3', beacons over TCP/443, and grants attackers keyboard/mouse lock, screen and audio capture, file transfer, and command execution -- with observed post-compromise activity including Impacket-based lateral movement and ProcDump credential dumping. Elsewhere, ClickFix lures also deliver Lumma S
Weaknesses (CWE)
CWE-290, CWE-346, CWE-451, CWE-522
Target sectors: legal, professional services, government administration, health, finance, education, non-profit organisation, manufacturing, energy, construction
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589.002, T1598.003, T1583.001, T1584.004, T1608.001, T1566.002, T1566.001, T1656, T1204.001, T1078