Tycoon is a phishing-as-a-service platform and adversary-in-the-middle phishing kit used to compromise Microsoft 365 and other enterprise accounts by relaying authentication traffic in real time. It is widely associated with campaigns that impersonate Microsoft login workflows, capture usernames and passwords, intercept multifactor authentication artifacts, and steal authenticated session cookies to bypass MFA and enable account takeover.
Tycoon is commonly deployed in credential phishing operations delivered through email-based lures, QR-code phishing, and redirect chains that abuse trusted services and cloud-hosted infrastructure. Observed campaigns have used document-sharing, HR, payroll, invoice, benefits, and holiday-themed pretexts, as well as fake OAuth application consent flows that redirect victims into Tycoon-powered phishing pages. The kit has also been linked to cloud-hosted phishing pages on legitimate platforms and to CAPTCHA-gated workflows intended to filter bots and hinder automated analysis.
Operationally, Tycoon provides synchronous relay capabilities characteristic of AiTM frameworks, allowing attackers to proxy victim authentication to legitimate services while harvesting credentials, MFA tokens or approvals, and session material. This enables downstream session hijacking and post-compromise abuse of Microsoft 365 environments. Tycoon activity has been linked to large-scale campaigns affecting hundreds of organizations and thousands of user accounts, with follow-on impacts including account takeover, business email compromise, data exposure, mailbox abuse, and persistence through malicious OAuth application registration or MFA method manipulation.
Tycoon is part of the broader commercialization of phishing operations, lowering the barrier to entry for threat actors by packaging phishing infrastructure and workflows as a service. It is frequently discussed alongside other AiTM kits such as Evilginx, EvilProxy, Sneaky2FA, and similar platforms. The malware primarily targets web-based enterprise authentication rather than a traditional endpoint operating system, but its observed abuse is centered on Microsoft 365 and Microsoft Entra ID users across a wide range of sectors and geographies.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The goal of the campaigns is to use OAuth applications as a gateway lure to conduct other activities, mostly to obtain access to Microsoft 365 accounts via MFA phishing.
не исключены и другие методы атаки, например, с помощью ... эксплойтов
The page presented the user's organization Azure Active Directory (AAD) or Okta Branding and was designed to harvest user credentials, multifactor authentication (MFA) tokens, and retrieve associated session cookies.
The credential phishing page presented the user's organization AAD (Azure Active Directory) Branding once email was provided and it was designed to harvest user credentials, 2FA token, and to retrieve an associated session cookie.
The credential phishing page presented the user's organization AAD (Azure Active Directory) Branding once email was provided and it was designed to harvest user credentials, 2FA token, and to retrieve an associated session cookie.
A typical adversary-in-the-middle (AiTM) attack begins with the victim receiving a phishing message containing a link to a malicious webpage design to mimic a legitimate login page. The fake domain is connected to a reverse proxy server, which relays traffic between the victim and the actual service.
используя в качестве трамплина уязвимые и открытые для RDP-доступа серверы
The page presented the user's organization Azure Active Directory (AAD) or Okta Branding and was designed to harvest user credentials, multifactor authentication (MFA) tokens, and retrieve associated session cookies.
A typical adversary-in-the-middle (AiTM) attack begins with the victim receiving a phishing message containing a link to a malicious webpage design to mimic a legitimate login page. The fake domain is connected to a reverse proxy server, which relays traffic between the victim and the actual service.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another AiTM phishing kit that shares hosting infrastructure with Kratos, but with different code and no analysis-level overlap in this article.
An adversary-in-the-middle phishing kit used to facilitate token/session theft during OAuth-themed phishing flows, helping attackers capture credentials/tokens and maintain access to Microsoft 365/Entra ID environments.
A phishing kit family hosted on legitimate cloud infrastructure (Microsoft Azure Blob Storage) to serve credential-harvesting pages while evading domain-reputation based detection.
Adversary-in-the-middle phishing kit used to take over Microsoft accounts; in the described incident it enabled follow-on persistence via mailbox rules and a malicious OAuth app.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.