Storm-1747 is the financially motivated cybercrime operation tracked by Microsoft as the developer, advertiser, and operator of the Tycoon 2FA phishing-as-a-service platform. Active since at least August 2023, it supplied subscribers with turnkey adversary-in-the-middle phishing infrastructure and campaign-management tooling used to impersonate enterprise identity services, especially Microsoft 365, Microsoft Entra ID, and Google Workspace. Tycoon 2FA proxies legitimate authentication workflows in real time, relays MFA challenges, captures credentials and authenticated session tokens, and enables account takeover despite conventional MFA methods. The platform provides phishing templates, lure-generation capabilities, redirect configuration, hosting and domain setup, victim tracking, and delivery of captured data to customers. Campaigns have used links and QR codes embedded in common document and web attachment formats, as well as compromised accounts to distribute follow-on phishing messages. Storm-1747 employs extensive defense evasion, including browser fingerprinting, automated-analysis detection, CAPTCHA-gated pages, dynamic decoy content, multi-stage redirect chains, code obfuscation, per-victim payload encryption, and rapid rotation of short-lived phishing infrastructure. Microsoft-focused activity has included post-compromise Graph API reconnaissance and abuse of device registration to establish persistence through attacker-controlled registered devices and device-bound tokens. The group has also been observed using infrastructure supplied by the RedVDS cybercrime service. Tycoon 2FA became one of the highest-volume AiTM phishing services observed globally, with activity affecting organizations across health care, education, financial services, government, and nonprofit sectors. Microsoft, Europol, law-enforcement authorities, and private-sector partners disrupted core Tycoon 2FA infrastructure in March 2026. Subsequent activity indicated that the operators and customers adapted their methods, including use of OAuth device-code phishing.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator of the Tycoon2FA phishing-as-a-service platform, renting an adversary-in-the-middle phishing kit to customers to steal credentials and session tokens and bypass traditional MFA.
Operates or is attributed with the Tycoon 2FA phishing-as-a-service campaign, conducting adversary-in-the-middle phishing to steal authenticated session tokens from Microsoft 365 and Google Workspace accounts and bypass MFA.
Highly prolific AiTM phishing platform responsible for a large share of Microsoft-blocked AiTM phishing attempts before rapidly recovering after disruption.
Highly prolific adversary-in-the-middle phishing platform operating at large scale before and after law-enforcement disruption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.