Tycoon2FA is a phishing-as-a-service adversary-in-the-middle platform that emerged in 2023 and became one of the most prolific enterprise-focused phishing kits targeting cloud identity services. It is tracked by Microsoft as Storm-1747 and has been associated with large-scale campaigns against Microsoft 365, Google services, Okta, DocuSign, and related SaaS environments across sectors including government, finance, healthcare, education, and non-profit organizations. The platform was commercially offered to other criminals through subscription-style access and provided a management panel for configuring lures, redirects, campaign infrastructure, and victim monitoring.
Its core function is to bypass conventional multifactor authentication by proxying live authentication sessions, capturing submitted credentials, and stealing authenticated session cookies or tokens for reuse. This enables session hijacking and follow-on access even when victims successfully complete MFA. Tycoon2FA has also been reported to support Microsoft 365 device-code phishing, abusing the OAuth device authorization flow so that victims authenticate on a legitimate Microsoft page while attackers receive tokens tied to a rogue device or application. Stolen access can facilitate business email compromise, cloud data theft, and further activity within compromised tenants.
Tycoon2FA commonly impersonates Microsoft 365 and Google-branded login workflows and uses phishing lures delivered through email attachments, QR codes, HTML content, SVG files, document-themed attachments, and links themed around shared files, HR, payroll, or signature requests. Campaigns have also used compromised mailboxes and reply-chain abuse to improve credibility. The platform emphasizes defense evasion through anti-bot checks, browser fingerprinting, custom CAPTCHA mechanisms, dynamic decoy pages, heavy JavaScript obfuscation, redirect chains, and rapidly rotating short-lived infrastructure. Captured data has been forwarded to operators through near-real-time notification channels, including Telegram-based workflows.
Tycoon2FA was disrupted in a coordinated action involving Microsoft, Europol, and partners in 2026, after which activity linked to the platform reportedly dropped sharply. Subsequent reporting indicates the kit resurfaced with updated capabilities, and researchers have also observed hybrid campaigns blending Tycoon2FA with Salty2FA components. Tycoon2FA remains a significant example of industrialized AiTM phishing infrastructure built to defeat non-phishing-resistant MFA and enable scalable credential and session theft in cloud environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Until a major global takedown, the most successful commercial kit for running this exact con was called Tycoon2FA. Its entire reason for existence is simple: to systematically defeat the one security defense we have spent a decade promoting as a silver bullet, multi-factor authentication.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
“Once obtained, the tokens allow attackers to access Microsoft 365 services, maintain persistent access through refresh tokens...”
Post-disruption campaigns also used URL shortener services, links inside legitimate presentation platforms, and compromised SharePoint environments from trusted contacts to redirect targets toward Tycoon2FA infrastructure.
Email phishing remains one of the most common ways attackers gain access to business accounts. During the second quarter of 2026, criminals continued to use fake login pages, malicious attachments, and convincing business messages to steal credentials or deliver malware.
Threat actors use CAPTCHA pages to delay detection and increase user interaction... By forcing users to engage with the CAPTCHA before accessing the payload, threat actors reduce the likelihood of automated scanning tools identifying the threat and increase the chances of successful credential harvesting or malware delivery.
It evades detection using real-time anti-bot screening, browser fingerprinting, self-hosted CAPTCHAs, heavy JavaScript obfuscation, and dynamic decoy pages.
Once the user completed the fake check, they were redirected to a spoofed sign-in page designed to steal their account credentials.
“whoever initiates the authentication request receives the resulting tokens. Once obtained, the tokens allow attackers to access Microsoft 365 services, maintain persistent access through refresh tokens, and conduct follow-on activities...”
The real platform is fully satisfied because you genuinely authenticated, so it issues a session cookie. The Theft: The relay keeps a copy of that token for the attacker and passes you through to the real site so nothing seems wrong.
“What began in 2023 as a straightforward AiTM credential harvester evolved into one of the most sophisticated PhaaS platforms documented.”
Once the user completed the fake check, they were redirected to a spoofed sign-in page designed to steal their account credentials.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service platform used to support credential theft campaigns, including fake sign-in workflows and adversary-in-the-middle style phishing operations.
A phishing service used to facilitate credential theft through fake sign-in workflows; Microsoft reported disrupting it and significantly reducing associated activity.
Tycoon2FA is a phishing-as-a-service platform used to conduct credential theft campaigns. In this report it is tied to QR code phishing, CAPTCHA-gated phishing, and broader phishing infrastructure that was disrupted, causing a sharp decline in related phishing volume.
Tycoon2FA is a phishing-as-a-service platform used for adversary-in-the-middle credential phishing. In this report it is tied to QR code phishing and CAPTCHA-gated phishing campaigns, with infrastructure shifts to .RU domains after disruption and a major decline in activity following Microsoft-led takedown efforts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.