Tycoon 2FA is a phishing-as-a-service platform used to conduct large-scale adversary-in-the-middle phishing and account takeover operations. First observed in August 2023, it is tracked by Microsoft as associated with Storm-1747. The platform primarily targets cloud identity accounts for Microsoft 365, Microsoft Entra ID, Google Workspace, Gmail, Outlook, OneDrive, SharePoint, and related single sign-on services, with healthcare and education among significantly affected sectors.
Its classic workflow presents convincing, organization-branded authentication pages through a reverse proxy that relays credentials and MFA challenges to the legitimate identity provider in real time. After authentication, it captures credentials and authenticated session cookies or tokens, enabling attackers to bypass conventional MFA protections through session replay. Tycoon 2FA also has used OAuth device-authorization phishing against Microsoft 365, tricking victims into authorizing attacker-controlled devices rather than directly proxying a sign-in flow.
The kit supports phishing-email delivery using links, QR codes, and lure documents, followed by redirect chains, CAPTCHA gates, and cloned sign-in portals. It employs browser fingerprinting, cloud-IP filtering, automation and debugger detection, JavaScript obfuscation, encrypted staged payloads, decoy pages, dynamic branding, and rapid infrastructure rotation to resist analysis and blocking. Microsoft-focused operations have also conducted post-compromise reconnaissance through Microsoft Graph and can register rogue Entra ID devices to obtain device-bound primary refresh tokens, which may survive ordinary user-session revocation.
Microsoft, Europol, and industry partners disrupted core Tycoon 2FA infrastructure in March 2026, seizing hundreds of associated domains. Subsequent activity demonstrated continued reuse and adaptation of its tooling and tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tycoon 2FA is a Phishing-as-a-Service platform that provides turnkey adversary-in-the-middle capabilities to bypass MFA and steal authenticated session tokens from Microsoft 365 and Google Workspace accounts.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Successful device code phishing attacks can lead to full account takeover, theft of sensitive information, fraud and business email compromise, lateral movement within a compromised environment, and even disruptive attacks like ransomware.
Once the operator console has a valid token, a rapid burst of Microsoft Graph API calls follows.
This article will explore the Tycoon 2FA phishing kit, a sophisticated Phishing-as-a-Service (PhaaS) platform... designed to bypass two-factor authentication (2FA) and multi-factor authentication (MFA) protections, primarily targeting Microsoft 365 and Gmail accounts.
Successful device code phishing attacks can lead to full account takeover, theft of sensitive information, fraud and business email compromise, lateral movement within a compromised environment, and even disruptive attacks like ransomware.
Once the operator console has a valid token, a rapid burst of Microsoft Graph API calls follows.
When a defender fires revokeSignInSessions... the device PRT remains valid because the device is a separate principal in Entra ID. | The kit uses the urn:ms-drs:enterpriseregistration.windows.net access token to POST endpoint EnrollmentServer/device with a locally-generated PKCS#10 CSR, synthetic device metadata and transport key blob.
Successful device code phishing attacks can lead to full account takeover, theft of sensitive information, fraud and business email compromise, lateral movement within a compromised environment, and even disruptive attacks like ransomware.
Once the operator console has a valid token, a rapid burst of Microsoft Graph API calls follows.
When a defender fires revokeSignInSessions... the device PRT remains valid because the device is a separate principal in Entra ID. | The kit uses the urn:ms-drs:enterpriseregistration.windows.net access token to POST endpoint EnrollmentServer/device with a locally-generated PKCS#10 CSR, synthetic device metadata and transport key blob.
The payload uses a custom two-stage cipher (Caesar shift + XOR with a PRNG-generated keystream) seeded with per-session values... Malicious JavaScript removes itself from the DOM after execution.
Primary Tactics & Techniques ... Masquerading (T1036) Look-alike domains, cloned login workflows, valid TLS certificates, and legitimate branding assets loaded from Microsoft CDNs create convincing replicas of real authentication portals.
Successful device code phishing attacks can lead to full account takeover, theft of sensitive information, fraud and business email compromise, lateral movement within a compromised environment, and even disruptive attacks like ransomware.
Once the operator console has a valid token, a rapid burst of Microsoft Graph API calls follows.
The kit is sophisticated enough to prompt users for their multi-factor authentication (MFA) code and can relay that code to Microsoft’s servers in real-time, effectively bypassing this critical security step.
Primary Tactics & Techniques ... Browser Information Discovery (T1528) Browser and environment fingerprinting (UA, screen, timezone, language) for filtering and geo-fencing.
The identity provider issues a session token. The proxy intercepts this token before it reaches the victim's browser.
Victims who end up interacting with a booby-trapped link embedded in the phishing email traverse through a five-stage redirect chain that implements anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate, before taking them to the final destination, which can be either an AitM proxy or a device code endpoint.
Role Discovery: transitiveRoleAssignments, memberOf/directoryRole, roleManagement/directory/roleAssignments.
Recon endpoints include transitiveRoleAssignments, memberOf/directoryRole, roleManagement/directory/roleAssignments... me/contactFolders/contacts.
The kit calls api.ipapi.is... to check the visitor's IP against a blocklist of cloud/hosting providers... Bot/tool detection checks for navigator.webdriver... PhantomJS, and 'Burp' in the user-agent string.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Adversary-in-the-middle phishing kit/proxy used downstream of the Bulletproof blind redirector to hijack authenticated Microsoft sessions and bypass MFA by intercepting session tokens.
Tycoon 2FA is a phishing-as-a-service adversary-in-the-middle kit that steals authenticated session tokens from Microsoft 365 and Google Workspace users, allowing attackers to bypass MFA. It uses reverse-proxy relays, WebSocket-based session relay, and device-code-grant abuse, and can establish persistence by registering rogue devices in Entra ID to obtain primary refresh tokens.
An adversary-in-the-middle phishing kit and PhaaS platform that proxies real Microsoft 365/Entra ID and Google Workspace login flows, captures post-MFA session tokens, and enables account takeover. The Microsoft-focused variant also abuses OAuth device code flow and can register rogue devices to obtain a primary refresh token for persistence.
An AiTM phishing kit/PhaaS platform that operates as a real-time reverse proxy for Microsoft 365/Entra ID and Google authentication. It relays victim credentials and MFA challenges to legitimate identity providers, intercepts post-MFA session tokens, and replays them for account takeover. The Microsoft variant additionally abuses OAuth device-code authentication and can register rogue devices to obtain PRT-based persistence that survives ordinary user session revocation. It uses anti-analysis checks, per-victim encrypted payloads, CAPTCHA lures, redirect chains, and Graph API reconnaissance after compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.