Tycoon 2FA is a commercial phishing-as-a-service platform first observed in August 2023 and associated with the threat operation Storm-1747. It specializes in adversary-in-the-middle phishing against Microsoft 365, Microsoft Entra ID, and Google Workspace accounts. Its reverse-proxy workflow relays credentials and multifactor authentication challenges between victims and legitimate identity providers, capturing usernames, passwords, authentication codes, and authenticated session cookies. Operators can replay stolen sessions to access accounts without completing another conventional MFA challenge. Subscription-based campaign management tools provide phishing templates, attachment lures, infrastructure configuration, victim tracking, and stolen-data retrieval or forwarding through Telegram.
Campaigns commonly begin with phishing emails containing links or QR codes, including those embedded in PDF, SVG, HTML, and PowerPoint attachments. Lures impersonate voicemail notifications, invoices, shared documents, and account-security messages. Compromised email accounts are also used to distribute phishing links to trusted contacts. The kit reproduces Microsoft and Google sign-in interfaces and can retrieve legitimate organizational branding to personalize them. Its evasion features include layered redirects, CAPTCHA gates, browser fingerprinting, hosting-provider and security-vendor filtering, automation detection, anti-debugging checks, encrypted and obfuscated JavaScript, and benign decoy pages for suspected analysts.
Microsoft-focused variants also support OAuth device-code phishing, persuading victims to complete genuine authentication and authorize token issuance to an attacker-controlled session rather than directly intercepting passwords. This technique abuses legitimate authentication instead of defeating MFA cryptographically. Associated operations conduct Microsoft Graph reconnaissance and can register rogue Entra ID devices to obtain primary refresh tokens, providing persistent access that ordinary user-session revocation alone may not eliminate. Tycoon 2FA has been used across numerous industries, with healthcare and education particularly affected, alongside finance, government, technology, and professional services. Microsoft, Europol, and partners disrupted its infrastructure in March 2026, but subsequent campaigns continued, including device-code variants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Despite attempts to take it down, Tycoon 2FA (Storm-1747) implements AiTM at scale.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Successful device code phishing attacks can lead to full account takeover, theft of sensitive information, fraud and business email compromise, lateral movement within a compromised environment, and even disruptive attacks like ransomware.
Once the operator console has a valid token, a rapid burst of Microsoft Graph API calls follows.
This article will explore the Tycoon 2FA phishing kit, a sophisticated Phishing-as-a-Service (PhaaS) platform... designed to bypass two-factor authentication (2FA) and multi-factor authentication (MFA) protections, primarily targeting Microsoft 365 and Gmail accounts.
Successful device code phishing attacks can lead to full account takeover, theft of sensitive information, fraud and business email compromise, lateral movement within a compromised environment, and even disruptive attacks like ransomware.
Once the operator console has a valid token, a rapid burst of Microsoft Graph API calls follows.
When a defender fires revokeSignInSessions... the device PRT remains valid because the device is a separate principal in Entra ID. | The kit uses the urn:ms-drs:enterpriseregistration.windows.net access token to POST endpoint EnrollmentServer/device with a locally-generated PKCS#10 CSR, synthetic device metadata and transport key blob.
Successful device code phishing attacks can lead to full account takeover, theft of sensitive information, fraud and business email compromise, lateral movement within a compromised environment, and even disruptive attacks like ransomware.
Once the operator console has a valid token, a rapid burst of Microsoft Graph API calls follows.
When a defender fires revokeSignInSessions... the device PRT remains valid because the device is a separate principal in Entra ID. | The kit uses the urn:ms-drs:enterpriseregistration.windows.net access token to POST endpoint EnrollmentServer/device with a locally-generated PKCS#10 CSR, synthetic device metadata and transport key blob.
The payload uses a custom two-stage cipher (Caesar shift + XOR with a PRNG-generated keystream) seeded with per-session values... Malicious JavaScript removes itself from the DOM after execution.
Primary Tactics & Techniques ... Masquerading (T1036) Look-alike domains, cloned login workflows, valid TLS certificates, and legitimate branding assets loaded from Microsoft CDNs create convincing replicas of real authentication portals.
Successful device code phishing attacks can lead to full account takeover, theft of sensitive information, fraud and business email compromise, lateral movement within a compromised environment, and even disruptive attacks like ransomware.
Once the operator console has a valid token, a rapid burst of Microsoft Graph API calls follows.
The kit is sophisticated enough to prompt users for their multi-factor authentication (MFA) code and can relay that code to Microsoft’s servers in real-time, effectively bypassing this critical security step.
Primary Tactics & Techniques ... Browser Information Discovery (T1528) Browser and environment fingerprinting (UA, screen, timezone, language) for filtering and geo-fencing.
The identity provider issues a session token. The proxy intercepts this token before it reaches the victim's browser.
Victims who end up interacting with a booby-trapped link embedded in the phishing email traverse through a five-stage redirect chain that implements anti-analysis protections, User-Agent fingerprinting, and a CAPTCHA gate, before taking them to the final destination, which can be either an AitM proxy or a device code endpoint.
Role Discovery: transitiveRoleAssignments, memberOf/directoryRole, roleManagement/directory/roleAssignments.
Recon endpoints include transitiveRoleAssignments, memberOf/directoryRole, roleManagement/directory/roleAssignments... me/contactFolders/contacts.
The kit calls api.ipapi.is... to check the visitor's IP against a blocklist of cloud/hosting providers... Bot/tool detection checks for navigator.webdriver... PhantomJS, and 'Burp' in the user-agent string.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Adversary-in-the-middle phishing toolkit associated with Storm-1747. It implements reverse-proxy phishing at scale, allowing authenticated session artifacts to be intercepted after victims complete legitimate authentication and MFA.
Adversary-in-the-middle phishing kit/proxy used downstream of the Bulletproof blind redirector to hijack authenticated Microsoft sessions and bypass MFA by intercepting session tokens.
Tycoon 2FA is a phishing-as-a-service adversary-in-the-middle kit that steals authenticated session tokens from Microsoft 365 and Google Workspace users, allowing attackers to bypass MFA. It uses reverse-proxy relays, WebSocket-based session relay, and device-code-grant abuse, and can establish persistence by registering rogue devices in Entra ID to obtain primary refresh tokens.
An adversary-in-the-middle phishing kit and PhaaS platform that proxies real Microsoft 365/Entra ID and Google Workspace login flows, captures post-MFA session tokens, and enables account takeover. The Microsoft-focused variant also abuses OAuth device code flow and can register rogue devices to obtain a primary refresh token for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.