Skip to main content
Mallory
2 malware families

Storm-1747

Also known asStorm-1747

Storm-1747 is the Microsoft-tracked threat actor associated with the Tycoon 2FA phishing-as-a-service (PhaaS) platform. The group developed, supported, advertised, and sold Tycoon 2FA to other cybercriminals, including via Telegram and Signal, and leased malicious infrastructure to enable large-scale adversary-in-the-middle (AiTM) phishing operations. Tycoon 2FA was first observed in August 2023 and was described as the most prolific AiTM/PhaaS platform observed by Microsoft in 2025 and into early 2026, at one point accounting for roughly 62% of AiTM phishing attempts Microsoft was blocking monthly and reaching more than 500,000 organizations per month. Microsoft and Europol disrupted Tycoon 2FA infrastructure in March 2026, seizing more than 300 domains; multiple reports state the platform resumed activity afterward. Storm-1747’s operations targeted Microsoft 365, Microsoft Entra ID, Google Workspace, Gmail, Outlook, OneDrive, SharePoint, and other enterprise sign-in workflows. The platform impersonated legitimate sign-in pages and used reverse-proxy/AiTM techniques to relay authentication in real time, steal credentials, MFA codes, authenticated session cookies, and session tokens, and thereby bypass traditional MFA protections. Reported lure delivery included phishing emails with PDF, SVG, HTML, DOCX, and PowerPoint attachments, as well as QR codes. The kit used multi-layer redirect chains and could dynamically load victim organization branding to make phishing pages appear authentic. Reported evasion and anti-analysis features included fake or self-hosted CAPTCHA pages, browser fingerprinting, anti-bot screening, filtering of cloud and hosting IP ranges, developer-tool blocking, automation and analysis-tool detection, heavy code obfuscation, custom JavaScript, dynamic decoy pages, and short-lived rapidly rotating domains and subdomains. Structural variants documented in the content include a WebSocket-based session relay and abuse of OAuth device code flow. For Microsoft-focused compromises, the platform was also reported to establish persistence by registering rogue devices in Entra ID and obtaining primary refresh tokens, allowing continued access even after session revocation. Storm-1747 is also mentioned as one of several threat actors observed leveraging RedVDS infrastructure, with that linkage described in the content as medium confidence based on infrastructure overlap and tool usage. The content also notes hypotheses of overlap between Tycoon2FA and hybrid Salty2FA/Tycoon2FA activity, suggesting a possible connection to Storm-1747, but this is presented as suggestive rather than confirmed. Aliases directly supported by the content: Tycoon 2FA, Tycoon2FA.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics28 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566×8
Phishing
T1566.001
Spearphishing Attachment
T1566.002×3
Spearphishing Link
TA0003
Persistence
2 techniques
T1205
Traffic Signaling
T1556×2
Modify Authentication Process
TA0005
Stealth
4 techniques
T1027×2
Obfuscated Files or Information
T1036
Masquerading
T1205
Traffic Signaling
T1497×2
Virtualization/Sandbox Evasion
TA0112
Defense Impairment
1 technique
T1556×2
Modify Authentication Process
TA0006
Credential Access
5 techniques
T1056
Input Capture
T1539×9
Steal Web Session Cookie
T1556×2
Modify Authentication Process
T1557×5
Adversary-in-the-Middle
T1621
Multi-Factor Authentication Request Generation
TA0007
Discovery
2 techniques
T1082
System Information Discovery
T1497×2
Virtualization/Sandbox Evasion
TA0009
Collection
3 techniques
T1056
Input Capture
T1114
Email Collection
T1114.003
Email Forwarding Rule
T1557×5
Adversary-in-the-Middle
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1205
Traffic Signaling
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
TA0040
Impact
1 technique
T1565
Data Manipulation
T1565.003
Runtime Data Manipulation
IOCS

Observables

4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping18

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables4

Domains, IPs, and hashes tied to this actor, refreshed continuously.