Cybercriminals are using a new phishing-as-a-service (PhaaS) platform called “ Tycoon 2FA ” and targeting Microsoft 365 and Gmail accounts , bypassing two-factor authentication (2FA).

Tycoon 2FA was discovered by analysts at Sekoia in October 2023, but has been active since at least August 2023, when the Saad Tycoon offered the platform via private Telegram channels.
There are similarities with other adversary-in-the-middle (AitM) platforms, such as Dadsec OTT, which means there may be code reuse or collaboration between the platform.
See also: Phishing attacks distribute StrelaStealer malware in Europe and the US
In 2024, the Tycoon 2FA platform released a new improved version. Currently, the service leverages 1,100 domains and has been used in thousands of attacks .
Tycoon 2FA
Tycoon 2FA attacks involve multiple steps. “Once the user completes the MFA challenge and the authentication is successful, the server in the middle records the session cookies,” Sekoia explains. This allows the attacker to replay a user’s session and bypass multi-factor authentication (MFA) mechanisms.
However, let's look in more detail at the stages of a Tycoon 2FA phishing attack , according to Sekoia's descriptions:
Stage 0: Attackers distribute malicious links via email, with embedded URLs or QR codes. Through these, victims gain access to phishing pages.
Stage 1: A security challenge (Cloudflare Turnstile) filters out bots, allowing only human users to proceed to the deceptive phishing website.
Stage 2: The background scripts extract the victim's email from the URLto customize the phishing attack.
Stage 3: Users are redirected to another part of the phishing website, getting closer to the fake login.
Stage 4: A fake Microsoft login page appears , aiming to steal credentials.
Stage 5: The Tycoon 2FA phishing platform mimics a 2FA challenge, interfering with the 2FA token and bypassing security.
Stage 6: Victims are directed to a page that appears legitimate.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Hackers exploit DDP sites for phishing attacks

Sekoia reports that the latest version of its phishing platform Tycoon 2FA has introduced significant modifications that improve phishing and evasion capabilities.
Key changes include updates to JavaScript and HTML code, changes to the resource retrieval order, and more extensive filtering to block traffic from bots.
As for the scale of the attacks, Sekoia says there is evidence of multiple cybercriminals using Tycoon 2FA for phishing operations. The Bitcoin associated with the operators has recorded more than 1,800 transactions since October 2019, with a notable increase since August 2023, when the kit was released.
'Tycoon 2FA' allows cybercriminals to bypass two-factor authentication (2FA), which increases the chances of successful phishing attacks.
See also: New phishing campaign targets the US with NetSupport RAT
Users of Microsoft 365 and Gmail accounts are at greater risk, as 'Tycoon 2FA' can bypass the security of these platforms.
These attacks can lead to the loss of confidential data, such as personal information, access credentials, and corporate data. In addition, there can be financial losses, as phishing attacks can be used to trick victims into handing over their credentials for bank accounts or other payment services.
Source: www.bleepingcomputer.com
