Microsoft 365 Users Targeted by Tycoon2FA Linked Phishing Attack to Steal Credentials
A recent development in phishing campaigns, attributed to the Tycoon2FA group, has emerged, specifically targeting Microsoft 365 users.
A recent development in phishing campaigns, attributed to the Tycoon2FA group, has emerged, specifically targeting Microsoft 365 users.
Security analysts have identified these campaigns utilizing malformed URLs with backslash characters, such as https:\\ , to bypass standard email security filters and evade URL-based detection systems.
Despite the incorrect format, modern web browsers can interpret and resolve these links, leading victims to credential harvesting sites.
Attackers utilize URLs with backslashes ( https:\\ ) instead of the standard forward slashes ( https:// ). This tactic exploits a vulnerability in email security filters that often overlook malformed URLs.
When users click these links, believing their email security would have filtered malicious content, browsers interpret the links correctly, leading to phishing landing pages.
This technique highlights a trend in phishing methods where unconventional tactics are employed to bypass advanced security measures in enterprise settings.
A recent development in phishing campaigns, attributed to the Tycoon2FA group, has emerged, specifically targeting Microsoft 365 users.
Phishing emails often mimic genuine Microsoft notifications, such as security alerts or two-factor authentication (2FA) prompts, to create urgency and prompt users to click the deceptive links.
Tycoon2FA, known for phishing-as-a-service (PhaaS), is behind these operations. The group targets Microsoft cloud users by spamming 2FA prompts and using advanced phishing kits to gather credentials.
These phishing sites are hosted on platforms like Microsoft Azure, Cloudflare Workers, and Google's DoubleClick, complicating takedown and detection efforts.
The campaign exploits URL encoding, redirect chains, and legitimate cloud hosting services for phishing content distribution.
Observed infrastructure includes domains resembling those of trusted services, enhancing social engineering success rates. Email subjects often relate to 2FA or account security to exploit user concerns about account security.
Organizations using Microsoft 365 should update email security solutions to recognize malformed URLs and advise users to verify unexpected authentication requests carefully.
Security teams should enhance detection rules for traditional and malformed URLs and implement browser-based protections to block access to newly identified malicious domains.
User education on phishing attack nuances and URL verification is crucial to prevent credential compromise.
IOC URL: hxxps[://]microsftmailonlinenyukmvdx2t[.]lgotsna[.]es/ - Typo-squatted domain targeting M365 users IOC URL: hxxps[://]googleads[.]g[.]doubleclick[.]net/pcs/click?adurl=%68%74%74%70%73%3A%2F%2F%34[…]%6E%65%74# - Redirect via encoded ad link IOC URL: hxxps[://]783784387348438743-fkhghccdfzc8e8cd[.]z02[.]azurefd[.]net/ - Azure-hosted phishing page IOC URL: hxxps[://]4839794398349343-g4eydqdkguhcdvgs[.]z02[.]azurefd[.]net - Azure-hosted credential harvesting site IOC URL: hxxps[://]sdnxk0t5-q[.]alt-bq-4o27qr9a[.]workers[.]dev - Cloudflare Workers disposable phishing IOC URL: hxxps[://]9kp6wgtaqr[.]cloudflareemail2109399[.]workers[.]dev - Cloudflare Workers disposable phishing
Based on reporting by GBHackers.
