Tycoon 2FA is a phishing-as-a-service (PhaaS) operation active since 2023 and widely regarded as one of the most prolific adversary-in-the-middle phishing platforms targeting cloud identities. It specializes in large-scale credential-harvesting campaigns against Microsoft 365, Gmail, and other cloud services, using reverse-proxy techniques to relay live authentication sessions, capture credentials and multifactor authentication responses, and steal authenticated session cookies for account takeover. The platform has been linked to very high phishing volume globally and has been used by a broad affiliate base. Tycoon 2FA commonly uses CAPTCHA or similar gating, browser fingerprinting, traffic filtering, multistage redirects, QR-code lures, malicious attachments, dynamically branded login pages, obfuscated scripts, anti-debugging, and anti-analysis controls to evade detection and hinder research. It has also used real-time session handling and encrypted exfiltration within its phishing workflow. Successful compromises have enabled follow-on activity including email exfiltration, internal phishing, spam, business email compromise, and persistence through stolen sessions. By 2025 and 2026, Tycoon 2FA evolved beyond classic AiTM phishing into OAuth device code phishing. In these campaigns, victims are socially engineered into completing a legitimate Microsoft device authorization flow that grants tokens to an attacker-controlled device rather than directly surrendering credentials. This shift allowed the operation and associated actors to obtain access and refresh tokens without credential capture, extending Tycoon 2FA’s tradecraft into session and token theft through legitimate cloud authentication workflows. The service has been sold through a subscription model and supported through affiliate-style operations, with reporting also referring to Tycoon2FA affiliates and service operators. Microsoft has tracked the platform as Storm-1747. Tycoon 2FA has been associated with widespread targeting of organizations worldwide, especially users of Microsoft cloud services, with observed victim sectors including education, healthcare, finance, technology, and government/public sector entities. A coordinated disruption led by Microsoft and Europol in March 2026 seized hundreds of domains and temporarily reduced activity, but the operators rapidly reworked hosting, domain registration patterns, and delivery mechanisms and resumed operations. Subsequent reporting indicates that while the branded service declined after the takedown, its code, techniques, and tradecraft were redistributed across affiliates, cloned deployments, and competing phishing kits. Known aliases include Tycoon2FA, tycoon_2fa, tycoon_2fa_affiliates, and tycoon_2fa_(service_operators).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AiTM phishing-as-a-service platform used for credential harvesting, MFA interception, and session-cookie theft to take over cloud accounts.
Associated actors were observed using device code phishing as the technique spread from state actors to cybercriminal groups.
A phishing-as-a-service operation whose disruption caused a major drop in phishing volume, especially QR code phishing and CAPTCHA-gated phishing. Its operators were forced to rework infrastructure and delivery mechanisms after the takedown.
Mentioned only as a comparison to a prior law-enforcement disruption of another phishing kit/service.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.