Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Microsoft 365 Users Targeted by Tycoon2FA Linked Phishing Attack to Steal Credentials

A recent development in phishing campaigns, attributed to the Tycoon2FA group, has emerged, specifically targeting Microsoft 365 users.

A recent development in phishing campaigns, attributed to the Tycoon2FA group, has emerged, specifically targeting Microsoft 365 users.

Security analysts have identified these campaigns utilizing malformed URLs with backslash characters, such as https:\\ , to bypass standard email security filters and evade URL-based detection systems.

Despite the incorrect format, modern web browsers can interpret and resolve these links, leading victims to credential harvesting sites.

Attackers utilize URLs with backslashes ( https:\\ ) instead of the standard forward slashes ( https:// ). This tactic exploits a vulnerability in email security filters that often overlook malformed URLs.

When users click these links, believing their email security would have filtered malicious content, browsers interpret the links correctly, leading to phishing landing pages.

This technique highlights a trend in phishing methods where unconventional tactics are employed to bypass advanced security measures in enterprise settings.

A recent development in phishing campaigns, attributed to the Tycoon2FA group, has emerged, specifically targeting Microsoft 365 users.
Sarah Dawson · Thehackingpost

Phishing emails often mimic genuine Microsoft notifications, such as security alerts or two-factor authentication (2FA) prompts, to create urgency and prompt users to click the deceptive links.

Tycoon2FA, known for phishing-as-a-service (PhaaS), is behind these operations. The group targets Microsoft cloud users by spamming 2FA prompts and using advanced phishing kits to gather credentials.

These phishing sites are hosted on platforms like Microsoft Azure, Cloudflare Workers, and Google's DoubleClick, complicating takedown and detection efforts.

The campaign exploits URL encoding, redirect chains, and legitimate cloud hosting services for phishing content distribution.

Observed infrastructure includes domains resembling those of trusted services, enhancing social engineering success rates. Email subjects often relate to 2FA or account security to exploit user concerns about account security.

Advertisement

Organizations using Microsoft 365 should update email security solutions to recognize malformed URLs and advise users to verify unexpected authentication requests carefully.

Security teams should enhance detection rules for traditional and malformed URLs and implement browser-based protections to block access to newly identified malicious domains.

User education on phishing attack nuances and URL verification is crucial to prevent credential compromise.

IOC URL: hxxps[://]microsftmailonlinenyukmvdx2t[.]lgotsna[.]es/ - Typo-squatted domain targeting M365 users IOC URL: hxxps[://]googleads[.]g[.]doubleclick[.]net/pcs/click?adurl=%68%74%74%70%73%3A%2F%2F%34[…]%6E%65%74# - Redirect via encoded ad link IOC URL: hxxps[://]783784387348438743-fkhghccdfzc8e8cd[.]z02[.]azurefd[.]net/ - Azure-hosted phishing page IOC URL: hxxps[://]4839794398349343-g4eydqdkguhcdvgs[.]z02[.]azurefd[.]net - Azure-hosted credential harvesting site IOC URL: hxxps[://]sdnxk0t5-q[.]alt-bq-4o27qr9a[.]workers[.]dev - Cloudflare Workers disposable phishing IOC URL: hxxps[://]9kp6wgtaqr[.]cloudflareemail2109399[.]workers[.]dev - Cloudflare Workers disposable phishing

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories