Storm-1747 is the Microsoft threat-actor designation for the financially motivated developers and operators of Tycoon 2FA, also styled Tycoon2FA, a phishing-as-a-service platform first observed in August 2023. The operation develops, advertises, supports, and rents phishing kits and infrastructure to cybercriminal customers, who conduct their own campaigns. Its subscription-based administration panel provides phishing templates, lure generation, hosting configuration, redirect management, victim tracking, and access to captured credentials and session tokens. The service has been marketed through Telegram and Signal. Tycoon 2FA primarily targets Microsoft 365, Microsoft Entra ID, and Google Workspace accounts. Its adversary-in-the-middle reverse proxy relays legitimate authentication and conventional MFA challenges while capturing passwords and authenticated session cookies, enabling account takeover without another authentication prompt. Campaigns reach organizations worldwide, including healthcare, education, financial services, government, and nonprofit organizations, with documented victims in the United States. Lures commonly use links or QR codes in document and web-format attachments, sometimes distributed from compromised accounts or within existing email conversations. Defense-evasion features include multistage redirects, browser fingerprinting, anti-bot screening, fake CAPTCHA gates, code obfuscation, automation and debugger detection, decoy pages, and rapidly rotating infrastructure. Captured credentials and tokens can be exported through the administration panel or forwarded through Telegram. Microsoft-focused variants also support OAuth device-code phishing, Microsoft Graph reconnaissance, and rogue Entra ID device registration to obtain primary refresh tokens for persistent access. In March 2026, Microsoft, Europol, national authorities, and industry partners disrupted Tycoon 2FA by seizing 330 infrastructure domains. Subsequent activity continued with changes to hosting and domain-registration patterns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with Tycoon 2FA, a commodity adversary-in-the-middle phishing offering that intercepts authenticated sessions at scale. The actor is mentioned as a background example rather than a primary subject.
Operator of the Tycoon2FA phishing-as-a-service platform, renting an adversary-in-the-middle phishing kit to customers to steal credentials and session tokens and bypass traditional MFA.
Operates or is attributed with the Tycoon 2FA phishing-as-a-service campaign, conducting adversary-in-the-middle phishing to steal authenticated session tokens from Microsoft 365 and Google Workspace accounts and bypass MFA.
Highly prolific AiTM phishing platform responsible for a large share of Microsoft-blocked AiTM phishing attempts before rapidly recovering after disruption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.