Saad Tycoon Group is the name associated with the operators and alleged developers behind Tycoon 2FA, a phishing-as-a-service platform used for large-scale credential harvesting and adversary-in-the-middle phishing that bypasses multifactor authentication by intercepting live authentication flows and stealing session cookies. The group has also been associated with the handle Mr_XaaD. Tycoon 2FA evolved from an earlier phishing kit observed in 2023 into a more capable 2FA-bypass platform in early 2024 and was marketed as a premium service to other criminals through Telegram-based sales and support channels. Operations attributed to this group relied on phishing lures such as payment notifications, voicemail messages, and legal-themed messages, often delivering links or QR-code-based redirects to counterfeit login portals. Tycoon 2FA commonly impersonated cloud authentication services, especially Microsoft 365, and dynamically customized phishing pages to match a victim organization’s branding. The platform used CAPTCHA-style gating, short-lived subdomains, obfuscated client-side code, anti-debugging and anti-copy protections, and encrypted exfiltration of captured data to hinder detection and analysis. A core capability was real-time interception of credentials and multifactor authentication events to capture active session tokens for subsequent account takeover. The service operated at significant scale, being linked to tens of thousands of phishing incidents and widespread unauthorized access affecting organizations globally. Its infrastructure and operations were disrupted in March 2026 through a coordinated law-enforcement and private-sector action led through Europol EC3 with major industry support. Saad Tycoon Group is best characterized as a financially motivated cybercriminal actor enabling downstream phishing and account-compromise operations through a subscription-based PhaaS model.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.