Tycoon 2FA is a large phishing-as-a-service operation and toolkit active since 2023 that became one of the most prolific platforms for adversary-in-the-middle phishing against cloud identities, especially Microsoft 365 and also Gmail. It is widely tracked as a financially motivated cybercriminal service and has also been referred to as Storm-1747 in Microsoft reporting. The platform is sold to affiliates through a subscription model and has been used in high-volume credential-harvesting campaigns that bypass multifactor authentication by relaying live authentication sessions and stealing session cookies and authentication tokens. Tycoon 2FA emerged from earlier large-scale phishing-kit activity and evolved into a mature ecosystem with operators and affiliates. Its campaigns commonly use business-themed lures such as voicemail, payment, document-signature, payroll, and policy notifications, delivered through links, PDFs, QR codes, HTML or SVG attachments, and trusted redirectors. The platform is known for CAPTCHA or Turnstile gating, anti-analysis checks, obfuscated scripts, dynamic branding of phishing pages to match the victim organization, and encrypted transmission of stolen data to backend infrastructure. It has been associated with short-lived domains, privacy-protected registrations, proxy infrastructure, and rapid rehosting after disruption. A defining capability of Tycoon 2FA has been adversary-in-the-middle phishing that captures credentials, multifactor authentication responses, and session cookies in real time, enabling account takeover without defeating MFA cryptographically. By 2025 and 2026, the operation also adopted OAuth device code phishing, abusing Microsoft’s legitimate device authorization flow to trick victims into authorizing attacker-controlled devices. In these campaigns, victims authenticate on genuine Microsoft infrastructure, but the approval grants tokens to the attacker, enabling persistent cloud access, reconnaissance, email abuse, and follow-on business email compromise or internal phishing. Post-compromise activity has included automated cloud logins, token reuse, and use of rotating proxy infrastructure. Tycoon 2FA has targeted organizations globally at very large scale, with especially strong evidence of targeting in the United States and the United Kingdom, and sectors including government, health care, financial services, education, and technology. Reporting has linked the platform to tens of millions of phishing emails per month at peak activity and to compromises affecting large numbers of organizations and users worldwide. The operation was disrupted in March 2026 through a coordinated action involving Microsoft, Europol, and partner organizations, including seizure of hundreds of domains forming core phishing and control infrastructure. Despite that disruption, operators and affiliates rapidly adapted by shifting hosting providers, domain patterns, proxy sources, and delivery mechanisms, while much of the core kit and tradecraft remained intact. Subsequent reporting indicates that Tycoon 2FA’s code, techniques, and affiliate ecosystem were redistributed across cloned deployments and competing phishing services, helping spread device code phishing and other identity-focused tradecraft more broadly across the phishing-as-a-service landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated actors were observed using device code phishing as the technique spread from state actors to cybercriminal groups.
A phishing-as-a-service operation whose disruption caused a major drop in phishing volume, especially QR code phishing and CAPTCHA-gated phishing. Its operators were forced to rework infrastructure and delivery mechanisms after the takedown.
Mentioned only as a comparison to a prior law-enforcement disruption of another phishing kit/service.
Established AiTM phishing platform targeting Microsoft 365 that has expanded to device code flow phishing, using anti-bot protections, obfuscated anti-analysis JavaScript, browser fingerprinting, and spoofed legal/document-signature lures.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.