Tycoon2FA is a phishing-as-a-service adversary-in-the-middle platform that emerged in 2023 and became one of the most prolific MFA-bypass phishing kits targeting cloud identity services. It is tracked by Microsoft under the threat actor designation Storm-1747 and has been widely used to impersonate Microsoft 365, Outlook, SharePoint, OneDrive, Gmail, Okta, and DocuSign login workflows. The platform enables operators to relay live authentication sessions, capture user credentials, and steal authenticated session cookies or tokens, allowing account takeover even when victims complete multifactor authentication. In later reporting, Tycoon2FA was also observed supporting Microsoft 365 device-code phishing, in which victims authorize attacker-controlled access through legitimate OAuth device flows, resulting in token theft without requiring password capture.
Tycoon2FA is operated as a commercial service rather than a single campaign. It has been advertised through criminal messaging channels and offered subscribers a web-based administration panel for configuring lures, redirects, hosting, victim tracking, and collection of stolen data. Campaigns commonly used phishing emails with HTML, PDF, SVG, Word, EML, and QR-code-based lures, as well as links themed around business workflows such as shared documents, HR, payroll, voicemail, and signing requests. The kit has also been associated with AiTM phishing activity affecting a broad range of sectors worldwide, including legal, government, healthcare, education, finance, and nonprofit organizations, and was described as a dominant driver of enterprise-targeted AiTM compromises before coordinated disruption efforts in 2026.
The platform emphasizes defense evasion. Reported tradecraft includes short-lived rotating infrastructure, believable subdomains, redirect chains through legitimate cloud services, JavaScript obfuscation, anti-bot screening, browser fingerprinting, custom CAPTCHA mechanisms, dynamic decoy pages, and anti-analysis logic intended to hinder researchers and automated scanners. Tycoon2FA has also been observed in hybridized campaigns blending elements of Salty2FA and Tycoon2FA, indicating modular reuse of infrastructure and execution chains across phishing-as-a-service ecosystems.
Tycoon2FA has been linked to large-scale phishing volume and widespread account compromise. Its post-compromise utility includes session hijacking, credential theft, access persistence through stolen tokens, and follow-on abuse such as business email compromise, cloud data theft, and lateral movement in cloud environments. Microsoft, Europol, and partners conducted disruption actions against the platform in 2026, significantly reducing observed activity for a period, although subsequent reporting indicated rebuilding and renewed operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Until a major global takedown, the most successful commercial kit for running this exact con was called Tycoon2FA. Its entire reason for existence is simple: to systematically defeat the one security defense we have spent a decade promoting as a silver bullet, multi-factor authentication.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
“Once obtained, the tokens allow attackers to access Microsoft 365 services, maintain persistent access through refresh tokens...”
Threat actors use CAPTCHA pages to delay detection and increase user interaction... By forcing users to engage with the CAPTCHA before accessing the payload, threat actors reduce the likelihood of automated scanning tools identifying the threat and increase the chances of successful credential harvesting or malware delivery.
It evades detection using real-time anti-bot screening, browser fingerprinting, self-hosted CAPTCHAs, heavy JavaScript obfuscation, and dynamic decoy pages.
The group behind the PhaaS platform... sells phishing kits that impersonate various enterprise application sign-in pages... Once the CAPTCHA had been successfully completed, the user would then be shown a fake sign-in page used to compromise their account credentials.
Once the user completed the fake check, they were redirected to a spoofed sign-in page designed to steal their account credentials.
This allows the operator to capture passwords, MFA responses, and authenticated session cookies, potentially enabling account takeover even after the victim completes a conventional MFA challenge.
“whoever initiates the authentication request receives the resulting tokens. Once obtained, the tokens allow attackers to access Microsoft 365 services, maintain persistent access through refresh tokens, and conduct follow-on activities...”
The platform relayed victims’ credentials and MFA responses to legitimate login services before capturing authenticated session cookies.
Tycoon2FA emerged in 2023 as a major AiTM phishing service targeting Microsoft 365, Gmail, and other cloud accounts.
Once the user completed the fake check, they were redirected to a spoofed sign-in page designed to steal their account credentials.
Capturing authenticated session material can provide account access even after a victim completes a conventional MFA challenge.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adversary-in-the-middle phishing platform used to proxy authentication flows and steal valid session cookies, enabling MFA bypass and initial access.
An adversary-in-the-middle phishing platform used to bypass MFA by proxying authentication and stealing valid session cookies, heavily used against law firms.
A phishing-as-a-service platform used to support credential theft campaigns, including fake sign-in workflows and adversary-in-the-middle style phishing operations.
A phishing service used to facilitate credential theft through fake sign-in workflows; Microsoft reported disrupting it and significantly reducing associated activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.