Tycoon 2FA is a phishing-as-a-service (PhaaS) platform used by cybercriminals to conduct adversary-in-the-middle credential theft campaigns, primarily against Microsoft 365 and Google accounts. Active since at least 2023, it is designed to bypass multi-factor authentication by relaying authentication flows in real time and stealing credentials, session cookies, and one-time authentication codes. The service lowers the barrier to entry for affiliates by providing phishing infrastructure, kits, and operational workflows that enable large-scale credential phishing. Tycoon is widely associated with AiTM phishing operations that impersonate enterprise login portals, especially Microsoft-branded authentication pages. Campaigns attributed to the platform have used email lures, QR-code phishing, and links embedded in documents and other file formats to direct victims to counterfeit sign-in pages. The platform has been observed hosting fake login content on cloud infrastructure and tailoring phishing pages dynamically based on the targeted account or organization. Reported capabilities include adapting to authentication responses, presenting organization-branded login experiences, and prompting for MFA codes in order to complete session hijacking. The platform employs layered anti-analysis and evasion measures. Reported tradecraft includes domain and environment validation, CAPTCHA gating, bot and scanner detection, debugger checks, staged JavaScript delivery, compressed and encoded payloads, in-memory execution techniques, obfuscation, and encrypted communications between client-side scripts and backend infrastructure. Tycoon phishing workflows have also been associated with telemetry collection and victim profiling to improve campaign effectiveness and reduce exposure to automated analysis. Tycoon operates within the broader cybercrime service ecosystem and has been referenced alongside related MFA-phishing services such as DadSec, Rockstar2FA, and FlowerStorm. Reporting has noted similarities in operational patterns and Telegram-enabled affiliate workflows across these platforms, though common tooling or ecosystem overlap does not by itself prove identical operators. Tycoon has also been linked to phishing-for-hire activity and to affiliates that previously used calendar invitation lures and other social-engineering delivery methods. The actor behind Tycoon is best characterized as a financially motivated cybercriminal service operator rather than a nation-state threat group. Its activity supports downstream account compromise, business email compromise, data theft, and follow-on intrusion activity by customers or affiliates. Tycoon is notable for industrializing MFA-bypass phishing and making sophisticated session-theft techniques accessible to a wider range of threat actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior phishing-as-a-service operation whose affiliates used calendar invites linking to credential-harvesting pages; mentioned only as background comparison.
A Telegram bot-powered phishing-as-a-service platform referenced as sharing features with FlowerStorm and Rockstar2FA.
Providing Phishing-as-a-Service (PhaaS) platforms to enable other threat actors to conduct phishing campaigns.
Tycoon is a phishing-for-hire platform specializing in adversary-in-the-middle MFA phishing, using platforms like Dadsec to capture credentials and session tokens.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.