Cyber Security News

Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners

Microsoft, Europol, and partners have dismantled the Tycoon 2FA phishing-as-a-service (PhaaS) platform, seizing 330 domains used for credential theft and MFA bypass. This coordinated action disrupts a service active since 2023 that powered tens of millions of phishing emails monthly.

Tycoon 2FA enabled cybercriminals to bypass multifactor authentication (MFA) via adversary-in-the-middle (AiTM) techniques, capturing credentials, session tokens, and real-time authentication codes for services like Microsoft 365 and Gmail.

Under a U.S. court order and Europol’s Cyber Intelligence Extension Programme (CIEP), Microsoft led the seizure of control panels and fake login pages, marking the first such cross-border public-private takedown.

Microsoft Alert

The platform accounted for 62% of phishing attempts Microsoft blocked by mid-2025, linking to 96,000 victims, including 55,000 Microsoft customers, with heavy impacts on healthcare and education sectors.

Phishing Volume (Source: Microsoft)

In November 2006, Tycoon 2FA nearly doubled its output from the previous month, likely due to the increase in holiday-season phishing activities and a rise in PhaaS (Phishing as a Service) subscriber activity. This surge resulted in approximately 33 million messages sent in a single month, making it the most prolific phishing service ever tracked by Microsoft.

The significant decline observed in January 2026 indicates a substantial disruption. Between November 2025 and January 2026, the volume of phishing messages fell by roughly 57.6% from its peak. This drop in activity aligns with Microsoft’s infrastructure seizures and coordinated efforts with Europol during that time frame.

Overall, the estimated volume of phishing messages from October 2025 to January 2026 was around 87.5 million, targeting over 500,000 organizations globally.

Over 100 Health-ISAC members were phished, causing operational disruptions like delayed patient care in New York hospitals and schools.

Partners, including Proofpoint, Intel 471, eSentire, Cloudflare, SpyCloud, Resecurity, Coinbase, and Shadowserver, provided telemetry, intelligence, and infrastructure takedowns across jurisdictions like Latvia and the UK.

Tycoon 2FA Phishing Kit Dismantled

Tycoon 2FA used realistic templates, reverse proxies, and dynamic JavaScript to relay victim inputs to legitimate services, hijacking sessions without alerts.

Tycoon 2FA Phishing Kit Dashboard (Source: Microsoft)

Evasion features included CAPTCHA, bot filtering, browser fingerprinting, Base64/LZ compression, DOM vanishing, and multi-domain redundancy for data exfiltration, according to the Microsoft report.

IOC ExampleTypeDescription
mapbox.stashiowio.usCredential ingestionPrimary backend for harvested data.
date.woosea.biz.idExfiltration relaySecondary data routing domain.
ifelse.rlcozx.esCross-origin trafficObfuscated POST requests.

Domains favored .ru, .com, and .es TLDs, with rapid rotation and DGA-like generation to evade blocks.

Operated by Saad Fridi (Pakistan-based) with marketing and support partners, it integrated with services like RedVDS for hosting and email spam. This reflects the impersonation economy, where disruptions cascade: prior takedowns of Lumma Stealer, RaccoonO365, and Fake ONNX forced shifts to Tycoon.

MITRE ATT&CK mappings highlight its focus:

TacticTechniqueName
ReconnaissanceT1598Phishing for Information
Resource DevelopmentT1583.001Acquire Infrastructure: Domains
Resource DevelopmentT1588.002Obtain Capabilities: Tool

Deploy passkeys, FIDO2 hardware keys, or phishing-resistant MFA over SMS/TOTP; enforce device trust and session controls. Monitor for proxy anomalies, unusual logins, and rapid domain rotations using threat intel feeds.

Block known IOCs and enable AI-driven email filters. Organizations should join ISACs for shared telemetry, as no single entity can counter scalable AiTM PhaaS alone.

Sustained disruptions raise costs for operators, prompting tighter access and shutdowns, reshaping the cybercrime market.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago