HomeSecurityDetails on the Tycoon 2FA Phishing Kit attack techniques

Details on Tycoon 2FA Phishing Kit attack techniques

The Tycoon 2FA phishing kit has emerged as one of the most sophisticated Phishing-as-a-Service platforms since its emergence in August 2023, designed specifically to bypass two-factor authentication and multi-factor authentication protections on Microsoft 365 and Gmail accounts.

See also: WordPress will require 2FA from plugin developers

Tycoon 2FA
Details on Tycoon 2FA Phishing Kit attack techniques

This advanced threat uses an Adversary-in-the-Middle, leveraging reverse proxies to host convincing phishing pages that perfectly replicate legitimate login interfaces, while capturing user credentials and session cookies in real time.

According to malware trend detector Any.run, Tycoon 2FA leads the way with over 64,000 reported incidents this year, making it one of the most prevalent phishing threats in the current landscape.

The attack spreads through multiple distribution channels, including malicious PDF documents, SVG files, PowerPoint presentations, and emails containing phishing links.

Malicious actors have also leveraged cloud storage platforms, such as Amazon S3 buckets, Canva, and Dropbox, to host fake login pages, making detection more difficult for traditional security solutions.

What makes this campaign particularly dangerous is its ability to steal identification codes even when two-factor authentication is enabled, rendering this security measure useless against the sophisticated interception techniques used by the kit.

Cybereason analysts found that the phishing kit implements multiple pre-redirect checks as defense mechanisms against detection, including domain verifications, CAPTCHA challenges, bot detection and scanning tools, as well as debugging checks that are actively sought by security researchers analyzing the code. These checks ensure that only genuine victims reach the final phishing page, while automated security tools and analyzers are redirected to harmless websites.

See also: Latrodectus Malware Loader: The successor to IcedID in phishing campaigns

Details on Tycoon 2FA Phishing Kit attack techniques
Details on Tycoon 2FA Phishing Kit attack techniques

The kit also demonstrates an advanced understanding of organizations' security policies by analyzing error messages from login attempts, allowing attackers to tailor their campaigns for maximum effectiveness.

The technical sophistication extends to the use of boilerplate that dynamically generate fake login pages based on real responses from Microsoft servers, creating a seamless experience that prompts users to enter their MFA codes, which are then transferred in real time to the legitimate servers, successfully bypassing this critical layer of security.

The attack progresses through a complex multi-stage JavaScript execution chain, designed to evade detection while collecting credentials. The initial HTML page contains a JavaScript file with a base64-encoded payload, compressed using the LZ-string, which decompresses and executes the hidden payload in memory.

The second stage uses a technique called the DOM Vanishing Act, where the malicious JavaScript code removes itself from the Document Object Model after execution, leaving no visible trace for security tools inspecting the page's code. The script contains three different base64-encoded payloads, each designed to execute under specific conditions.

The first payload uses XOR cipher obfuscation and is only executed when window.location.pathname.split contains an exclamation mark or dollar sign, confirming that the user arrived via the intended malicious link and not via an automated scan.

See also: Darcula: New phishing service targets Android and iOS users

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Details on Tycoon 2FA Phishing Kit attack techniques
Details on Tycoon 2FA Phishing Kit attack techniques

The email extraction process creates a custom string by appending “WQ” to the victim’s email address before exporting it to the command and control server via a POST request, where the server responds with AES-encoded payloads that are decrypted using the CryptoJS. When victims enter credentials on the fake login page, the attacker acting as a middleman immediately receives the information and submits it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS