Saad Tycoon Group is an alleged operator/developer group associated with the Tycoon 2FA phishing-as-a-service (PhaaS) platform, and is also associated with the handle Mr_XaaD. The provided content states that Tycoon 2FA was sold and supported primarily through Telegram channels operated by its alleged developers, often associated with the Saad Tycoon Group or Mr_XaaD handles. Tycoon 2FA is described as a large-scale PhaaS platform used for credential harvesting and adversary-in-the-middle (AITM) phishing that bypasses MFA by intercepting live logins and stealing active session cookies. The platform used lures such as payment confirmations, voicemail notifications, and court orders; malicious links or PDF attachments with QR codes; CAPTCHA or Cloudflare Turnstile gating; dynamically branded fake login pages; obfuscated scripts; anti-debugging and anti-copy mechanisms; regex-based validation of victim input; and AES-encrypted exfiltration to command-and-control infrastructure. It commonly impersonated Microsoft 365 and other cloud providers, used short-lived subdomains, and hid backend infrastructure behind Cloudflare with privacy-protected registrations. The content does not attribute a nation-state affiliation to Saad Tycoon Group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.