Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Tycoon 2FA Phishing Kit Evades MFA on Key Platforms

Tycoon 2FA Phishing Kit Evades MFA on Key Platforms

Posted on May 27, 2026 By CWS

The Tycoon 2FA phishing kit has emerged as a formidable threat in the cybersecurity landscape since August 2023. Designed as a Phishing-as-a-Service (PhaaS) platform, it allows cybercriminals to rent and deploy the kit with minimal effort. The primary target of Tycoon 2FA is to hijack authenticated session tokens from Microsoft 365 and Google Workspace accounts, bypassing multi-factor authentication (MFA) measures.

Impact and Reach of Tycoon 2FA

This phishing tool poses a significant risk as it circumvents MFA entirely. During its peak, Tycoon 2FA was responsible for about 62% of phishing attempts intercepted by Microsoft, affecting over half a million organizations monthly. The campaign was linked to a threat actor known as Storm-1747 and is prominently featured in malware trend trackers, such as ANY.RUN.

Elastic Security Labs has analyzed the kit’s operations within Microsoft Entra ID and Google Workspace. Their findings reveal that Tycoon 2FA uses two main structural variants—WebSocket-based session relay and device-code-grant abuse—to exploit different cloud identity platforms, highlighting its deep integration into the phishing ecosystem.

Resilience and Adaptation

Despite a coordinated takedown in March 2026 led by Microsoft and Europol, which resulted in the seizure of over 300 domains, the operators of Tycoon 2FA quickly adapted. Within weeks, they resumed their activities, employing infrastructure changes and blending their tactics with OAuth Device Code phishing, demonstrating their professionalism and resourcefulness.

The Tycoon 2FA’s persistence and sophistication make it a crucial threat to address. Organizations relying solely on traditional MFA are vulnerable, as the kit’s session token theft bypasses these defenses. Understanding the inner workings of Tycoon 2FA is vital for developing effective protective measures.

Technical Operation and Defense Strategies

Tycoon 2FA does not capture credentials in the traditional sense. Instead, it acts as a reverse proxy, intercepting session tokens without the victim’s knowledge. The attack typically begins with a phishing email containing a link or QR code, redirecting the victim to a convincing replica of the legitimate login page. Once the MFA process is completed, the kit captures the session cookie, granting attackers access to the account without further authentication prompts.

Elastic recommends implementing phishing-resistant MFA solutions like FIDO2 security keys to counteract these tactics. Additional measures include enforcing device compliance, blocking unauthorized device code flows, and enabling token protection. Security teams must also thoroughly enumerate and remove registered devices before revoking sessions to disrupt the kit’s persistence mechanisms.

Indicators of Compromise (IoCs) identified by Elastic Security Labs provide crucial insights into Tycoon 2FA’s operations, helping organizations recognize and counteract this sophisticated threat.

For the latest updates, follow us on Google News, LinkedIn, and X. Set Cyber Security News as a preferred source for timely cybersecurity insights.

Cyber Security News Tags:Cybersecurity, Elastic Security Labs, Google Workspace, MFA evasion, Microsoft 365, phishing kit, phishing-as-a-service, session token theft, Storm-1747, Tycoon 2FA

Post navigation

Previous Post: Grandoreiro Malware Threatens Portuguese and Latin American Banks

Related Posts

Highly Sophisticated macOS DigitStealer Employs Multi-Stage Attacks to Evade detection Highly Sophisticated macOS DigitStealer Employs Multi-Stage Attacks to Evade detection Cyber Security News
New Vulnerabilities in React Server Components Allow DoS Attacks and Source Code Leaks New Vulnerabilities in React Server Components Allow DoS Attacks and Source Code Leaks Cyber Security News
GitLab High-Severity Vulnerabilities Let Attackers Crash Instances GitLab High-Severity Vulnerabilities Let Attackers Crash Instances Cyber Security News
Critical Hikvision Vulnerability Risks Global Security Breaches Critical Hikvision Vulnerability Risks Global Security Breaches Cyber Security News
Qilin Emerged as The Most Active Group, Exploiting Unpatched Fortinet Vulnerabilities Qilin Emerged as The Most Active Group, Exploiting Unpatched Fortinet Vulnerabilities Cyber Security News
OpenAI Boosts AI Security by Acquiring Promptfoo OpenAI Boosts AI Security by Acquiring Promptfoo Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Tycoon 2FA Phishing Kit Evades MFA on Key Platforms
  • Grandoreiro Malware Threatens Portuguese and Latin American Banks
  • Iranian Hackers Implicated in LA Metro Cyberattack
  • Cybercriminals Target FIFA World Cup Fans with Fake Sites
  • GlassWorm Botnet Dismantled by Cybersecurity Experts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Tycoon 2FA Phishing Kit Evades MFA on Key Platforms
  • Grandoreiro Malware Threatens Portuguese and Latin American Banks
  • Iranian Hackers Implicated in LA Metro Cyberattack
  • Cybercriminals Target FIFA World Cup Fans with Fake Sites
  • GlassWorm Botnet Dismantled by Cybersecurity Experts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark