Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners
## Dismantling of Tycoon 2FA Phishing Platform
Dismantling of Tycoon 2FA Phishing Platform
Microsoft, in collaboration with Europol and other partners, has dismantled the Tycoon 2FA phishing-as-a-service (PhaaS) platform. This operation led to the seizure of 330 domains associated with credential theft and multifactor authentication (MFA) bypass. The service, operational since 2023, facilitated the distribution of tens of millions of phishing emails monthly.
The Tycoon 2FA platform leveraged adversary-in-the-middle (AiTM) techniques to capture credentials and session tokens, enabling cybercriminals to bypass MFA for services such as Microsoft 365 and Gmail.
Following a U.S. court order and under the Europol Cyber Intelligence Extension Programme (CIEP), Microsoft led efforts to seize control panels and fake login pages. This marks the first cross-border public-private takedown of its kind.
By mid-2025, Tycoon 2FA was linked to 62% of the phishing attempts blocked by Microsoft, affecting 96,000 victims, including 55,000 Microsoft customers, with significant impacts on the healthcare and education sectors.
In November 2006, Tycoon 2FA's phishing activity nearly doubled from the previous month, attributed to heightened phishing activities during the holiday season and increased PhaaS subscriber activity. Approximately 33 million messages were sent in that month alone, marking it as one of the most prolific phishing services tracked by Microsoft.
A significant decline in activity was observed by January 2026, with phishing message volumes falling by approximately 57.6% from their peak. This decrease aligns with Microsoft's infrastructure seizures and coordinated efforts with Europol during this period.
Overall, from October 2025 to January 2026, approximately 87.5 million phishing messages were estimated to have been sent, targeting over 500,000 organizations worldwide. More than 100 Health-ISAC members were affected, leading to operational disruptions such as delayed patient care in New York hospitals and schools.
Partners, including Proofpoint, Intel 471, eSentire, Cloudflare, SpyCloud, Resecurity, Coinbase, and Shadowserver, contributed to telemetry, intelligence, and infrastructure takedowns across jurisdictions, including Latvia and the UK.
Microsoft, in collaboration with Europol and other partners, has dismantled the Tycoon 2FA phishing-as-a-service (PhaaS) platform.
Tycoon 2FA utilized realistic templates, reverse proxies, and dynamic JavaScript to relay victim inputs to legitimate services, effectively hijacking sessions without triggering alerts. Evasion techniques included CAPTCHA, bot filtering, browser fingerprinting, Base64/LZ compression, DOM vanishing, and multi-domain redundancy for data exfiltration, according to the Microsoft report .
IOC Example Type Description
mapbox.stashiowio.us Credential ingestion Primary backend for harvested data.
date.woosea.biz.id Exfiltration relay Secondary data routing domain.
ifelse.rlcozx.es Cross-origin traffic Obfuscated POST requests.
Domains used .ru, .com, and .es TLDs, featuring rapid rotation and DGA-like generation to evade blocks. The operation was spearheaded by Saad Fridi, based in Pakistan, with marketing and support partners. Integration with services like RedVDS for hosting and email spam illustrates the broader impersonation economy.
MITRE ATT&CK mappings highlight the platform's focus:
Tactic Technique Name
Reconnaissance T1598 Phishing for Information
Resource Development T1583.001 Acquire Infrastructure: Domains
Resource Development T1588.002 Obtain Capabilities: Tool
Organizations are advised to deploy passkeys, FIDO2 hardware keys, or phishing-resistant MFA over SMS/TOTP, enforce device trust, and implement session controls. Monitoring for proxy anomalies, unusual logins, and rapid domain rotations through threat intelligence feeds is recommended. Blocking known IOCs and enabling AI-driven email filters are also essential. Participation in ISACs for shared telemetry is crucial, as no single entity can counter scalable AiTM PhaaS alone.
Sustained disruptions lead to increased operational costs for cybercriminal operations, prompting tighter access controls and shutdowns, thereby reshaping the cybercrime market.
Based on reporting by Cyber Security News.
