Threat researchers reported an ongoing credential-harvesting operation attributed to the Tycoon 2FA phishing kit, repeatedly leveraging newly registered *.contractors domains to host convincing Gmail and Microsoft 365/Outlook login lures. Observed pretexts include ICANN-related “email verification,” document-sharing prompts, and account-security warnings, with consistent infrastructure and execution flow across waves of activity.
Technical analysis of the phishing HTML/JavaScript and runtime behavior indicates MFA-aware logic and extensive anti-analysis tradecraft typical of Tycoon 2FA, including developer-tools and sandbox/analysis-environment detection, debugger timing checks, and forced redirects/termination when inspection is detected. The campaign’s use of obfuscation and encrypted runtime loaders is intended to hinder static and dynamic analysis while enabling real-time credential capture against enterprise email identities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A Reddit post on r/netsec highlighted the Tycoon 2FA phishing campaign and pointed readers to the external technical analysis. The post amplified awareness of the campaign's abuse of *.contractors domains for Gmail and Microsoft 365 credential harvesting.
A malware-analysis blog published technical findings with high-confidence attribution of the campaign to the Tycoon 2FA phishing kit. The write-up documented observed URLs, lures, execution flow, anti-analysis behavior, and noted the listed infrastructure represented only a subset of the broader campaign.
An ongoing phishing campaign used newly registered *.contractors domains, along with related infrastructure, to deliver Gmail and Microsoft 365 credential-harvesting pages. The operation employed Tycoon 2FA-style MFA-aware phishing flows, fake CAPTCHA gates, obfuscated client-side code, and benign decoy redirects to evade analysis and prolong domain use.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcemalwr-analysis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.