Rockstar2FA is a phishing-as-a-service platform focused on adversary-in-the-middle credential and multifactor authentication token theft, primarily through impersonation of widely used cloud and software-as-a-service login portals, especially Microsoft sign-in pages. It is regarded as an updated evolution of the DadSec phishing service and has been discussed alongside related platforms such as Tycoon and FlowerStorm due to shared portal structure, backend communications patterns, and Telegram-enabled operator workflows. DadSec has previously been associated with Storm-1575. The service enabled customers to purchase and manage phishing campaigns through Telegram and provided tenant-specific phishing pages for use in operations. Its infrastructure used decoy pages to mask phishing destinations from direct visitors, while credential-harvesting portals captured usernames, passwords, and MFA tokens and exfiltrated them to backend servers. Observed tradecraft included use of cloud-hosted front-end components, backend PHP-based collection logic, and operational patterns consistent with large-scale phishing kit deployment. Rockstar2FA was highly active through mid-2024 and appears to have suffered a significant infrastructure disruption in November 2024. The disruption affected phishing portals, decoy pages, and associated Telegram control channels, and available evidence indicates a backend technical failure rather than a confirmed law-enforcement takedown. After this disruption, activity from FlowerStorm increased markedly. Although Rockstar2FA and FlowerStorm likely share common ancestry and substantial technical similarities, attribution to the same operators is not established at high confidence. Rockstar2FA is best characterized as a financially motivated cybercriminal service supporting credential theft, session theft, and follow-on account compromise rather than ransomware operations. Its core capability set centers on initial access through phishing, theft of credentials and authentication material, and exfiltration of stolen data from phishing workflows.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prolific phishing-as-a-service operation that sold phishing campaigns through Telegram, used decoy pages and counterfeit Microsoft login portals, and harvested credentials and MFA tokens before suffering a major infrastructure disruption in November 2024.
Rockstar 2FA is a phishing group or platform using adversary-in-the-middle MFA phishing kits, leveraging Telegram for C2, and targeting organizations for credential and token theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.