Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners

## Dismantling of Tycoon 2FA Phishing Platform

Dismantling of Tycoon 2FA Phishing Platform

Microsoft, in collaboration with Europol and other partners, has dismantled the Tycoon 2FA phishing-as-a-service (PhaaS) platform. This operation led to the seizure of 330 domains associated with credential theft and multifactor authentication (MFA) bypass. The service, operational since 2023, facilitated the distribution of tens of millions of phishing emails monthly.

The Tycoon 2FA platform leveraged adversary-in-the-middle (AiTM) techniques to capture credentials and session tokens, enabling cybercriminals to bypass MFA for services such as Microsoft 365 and Gmail.

Following a U.S. court order and under the Europol Cyber Intelligence Extension Programme (CIEP), Microsoft led efforts to seize control panels and fake login pages. This marks the first cross-border public-private takedown of its kind.

By mid-2025, Tycoon 2FA was linked to 62% of the phishing attempts blocked by Microsoft, affecting 96,000 victims, including 55,000 Microsoft customers, with significant impacts on the healthcare and education sectors.

In November 2006, Tycoon 2FA's phishing activity nearly doubled from the previous month, attributed to heightened phishing activities during the holiday season and increased PhaaS subscriber activity. Approximately 33 million messages were sent in that month alone, marking it as one of the most prolific phishing services tracked by Microsoft.

A significant decline in activity was observed by January 2026, with phishing message volumes falling by approximately 57.6% from their peak. This decrease aligns with Microsoft's infrastructure seizures and coordinated efforts with Europol during this period.

Overall, from October 2025 to January 2026, approximately 87.5 million phishing messages were estimated to have been sent, targeting over 500,000 organizations worldwide. More than 100 Health-ISAC members were affected, leading to operational disruptions such as delayed patient care in New York hospitals and schools.

Partners, including Proofpoint, Intel 471, eSentire, Cloudflare, SpyCloud, Resecurity, Coinbase, and Shadowserver, contributed to telemetry, intelligence, and infrastructure takedowns across jurisdictions, including Latvia and the UK.

Microsoft, in collaboration with Europol and other partners, has dismantled the Tycoon 2FA phishing-as-a-service (PhaaS) platform.
Noah Kensington · Thehackingpost

Tycoon 2FA utilized realistic templates, reverse proxies, and dynamic JavaScript to relay victim inputs to legitimate services, effectively hijacking sessions without triggering alerts. Evasion techniques included CAPTCHA, bot filtering, browser fingerprinting, Base64/LZ compression, DOM vanishing, and multi-domain redundancy for data exfiltration, according to the Microsoft report .

IOC Example Type Description

mapbox.stashiowio.us Credential ingestion Primary backend for harvested data.

date.woosea.biz.id Exfiltration relay Secondary data routing domain.

ifelse.rlcozx.es Cross-origin traffic Obfuscated POST requests.

Domains used .ru, .com, and .es TLDs, featuring rapid rotation and DGA-like generation to evade blocks. The operation was spearheaded by Saad Fridi, based in Pakistan, with marketing and support partners. Integration with services like RedVDS for hosting and email spam illustrates the broader impersonation economy.

MITRE ATT&CK mappings highlight the platform's focus:

Advertisement

Tactic Technique Name

Reconnaissance T1598 Phishing for Information

Resource Development T1583.001 Acquire Infrastructure: Domains

Resource Development T1588.002 Obtain Capabilities: Tool

Organizations are advised to deploy passkeys, FIDO2 hardware keys, or phishing-resistant MFA over SMS/TOTP, enforce device trust, and implement session controls. Monitoring for proxy anomalies, unusual logins, and rapid domain rotations through threat intelligence feeds is recommended. Blocking known IOCs and enabling AI-driven email filters are also essential. Participation in ISACs for shared telemetry is crucial, as no single entity can counter scalable AiTM PhaaS alone.

Sustained disruptions lead to increased operational costs for cybercriminal operations, prompting tighter access controls and shutdowns, thereby reshaping the cybercrime market.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories