Tycoon2FA is a phishing-as-a-service adversary-in-the-middle platform that emerged in 2023 and became one of the most prolific MFA-bypass phishing kits targeting cloud identity services. It is tracked by Microsoft as Storm-1747 and has been widely used to impersonate Microsoft 365, Outlook, SharePoint, OneDrive, Gmail, Okta, and DocuSign login workflows. The platform enables operators to relay live authentication sessions, capture usernames and passwords, intercept session cookies and tokens issued after successful authentication, and reuse those artifacts to hijack authenticated sessions even when multifactor authentication is enabled. Reported post-compromise outcomes include account takeover, business email compromise, data theft, and lateral movement in cloud environments.
Tycoon2FA is operated as a commercial service rather than a single campaign. It has been advertised through criminal messaging channels and provides customers with a web-based administration panel for configuring lures, redirects, hosting, and victim tracking. Campaign delivery has commonly relied on phishing emails using attachments or embedded content themed as shared documents, voicemails, HR or payroll notices, and e-signature requests. Observed lure formats include PDF, HTML, SVG, Word, EML, and QR-code-based content. The platform has also been linked to campaigns abusing legitimate cloud and collaboration services as redirectors or hosting layers, and later reporting indicates support for Microsoft 365 device-code phishing, in which victims are tricked into authorizing attacker-controlled access through Microsoft’s legitimate device login flow.
The platform places strong emphasis on defense evasion. Reported features include heavy JavaScript obfuscation, anti-bot screening, browser fingerprinting, custom CAPTCHA logic, dynamic decoy pages, multi-hop redirect chains, short-lived rotating infrastructure, and anti-analysis checks intended to block researchers and automated scanning. Tycoon2FA has also been observed in hybridized campaigns that blend Salty2FA-style early stages with Tycoon2FA execution chains, complicating attribution and weakening static detections.
Tycoon2FA has affected organizations globally across sectors including legal, finance, healthcare, education, government, non-profit, manufacturing, telecommunications, retail, and logistics. It was identified as a major driver of AiTM account compromise activity against enterprise and legal-sector targets through 2025 and into 2026. A coordinated disruption effort by Microsoft, Europol, and partners significantly reduced observed activity for a period, but subsequent reporting indicates the platform or related operations resumed and adapted after the takedown.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The researchers also found similarities between the campaign's first-stage JavaScript and Tycoon2FA device code harvesting activity.
Until a major global takedown, the most successful commercial kit for running this exact con was called Tycoon2FA. Its entire reason for existence is simple: to systematically defeat the one security defense we have spent a decade promoting as a silver bullet, multi-factor authentication.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
“Once obtained, the tokens allow attackers to access Microsoft 365 services, maintain persistent access through refresh tokens...”
The campaigns used fake accounts impersonating senior executives to send document-sharing notifications from legitimate Notion infrastructure. | A financially motivated threat actor has been observed abusing free Notion accounts, malicious PDFs and device code phishing to harvest authentication tokens from targeted organizations.
It evades detection using real-time anti-bot screening, browser fingerprinting, self-hosted CAPTCHAs, heavy JavaScript obfuscation, and dynamic decoy pages.
The fetched content is generally a credential-harvesting page impersonating a widely used login such as Microsoft 365, Google Workspace or Adobe.
[AiTM portals] capture the resulting session token, and thereby defeat multifactor authentication.
“whoever initiates the authentication request receives the resulting tokens. Once obtained, the tokens allow attackers to access Microsoft 365 services, maintain persistent access through refresh tokens, and conduct follow-on activities...”
Increasingly these pages are not simple clones but adversary-in-the-middle (AiTM) portals: they relay what the victim types to the real login service in real time.
The fetched content is generally a credential-harvesting page impersonating a widely used login such as Microsoft 365, Google Workspace or Adobe.
Capturing authenticated session material can provide account access even after a victim completes a conventional MFA challenge.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing platform associated here with device code harvesting activity; researchers found overlapping scripts and assessed with moderate confidence that the actor was a customer of the platform.
An adversary-in-the-middle phishing platform used to proxy authentication flows and steal valid session cookies, enabling MFA bypass and initial access.
An adversary-in-the-middle phishing platform used to bypass MFA by proxying authentication and stealing valid session cookies, heavily used against law firms.
A phishing-as-a-service platform used to support credential theft campaigns, including fake sign-in workflows and adversary-in-the-middle style phishing operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.