Cyber Security News

Tycoon 2FA Phishing Kit Using Specially Crafted Code To Evade Detection

The cybersecurity landscape faces a growing threat with the emergence of the Tycoon 2FA phishing kit, a sophisticated Phishing-as-a-Service (PhaaS) platform designed to bypass MFA and evade detection.

First identified in August 2023, Tycoon 2FA has undergone significant updates, making it one of the most formidable tools for cybercriminals targeting services like Microsoft 365 and Gmail.

Tycoon 2FA utilizes an Adversary-in-the-Middle (AiTM) approach, employing a reverse proxy server to intercept user credentials and session cookies.

The phishing process begins with victims being lured through malicious links in emails or QR codes. A Cloudflare Turnstile challenge then filters out bots, ensuring only human users proceed.

Here, the security analysts noted that the users are subsequently redirected to a fake login page mimicking Microsoft or Google authentication portals, where their credentials and MFA codes are captured in real-time.

Actual phishing page these emails lead to is usually a fake Microsoft login page (Source – Barracuda)

Finally, session cookies are intercepted during the MFA process, allowing attackers to gain unauthorized access without needing the victim’s credentials again.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Innovations in Evasion

The latest version of Tycoon 2FA, observed in November 2024, incorporates advanced tactics to obstruct analysis and detection:

  • Obstructive Source Code: The phishing pages use specially crafted JavaScript and HTML code that omits traditional resource calls, complicating automated analysis.
  • Dynamic Code Generation: Each execution generates unique code, evading signature-based detection systems.
  • Blocking Security Tools: The kit detects penetration-testing tools like Burp Suite and redirects users to blank pages if such tools are identified.
  • Keystroke Monitoring: It listens for developer shortcuts or inspection keystrokes, blocking actions or redirecting users to legitimate sites like OneDrive.
  • Context Menu Disabling: Right-click menus are disabled to prevent manual inspection of web elements.
  • Clipboard Manipulation: Attempts to copy text from the phishing page result in overwritten clipboard content, hindering data extraction.

Tycoon 2FA’s ability to bypass MFA protections poses a severe risk to organizations relying on session-based authentication.

By leveraging session cookies, attackers can maintain persistent access even if credentials are changed.

This capability has made Tycoon 2FA a popular choice among cybercriminals, with over 1,100 domains implicated in phishing campaigns.

Financially, the operators of Tycoon 2FA have profited significantly, with reports indicating cryptocurrency earnings nearing $400,000 by March 2024.

The kit is sold on platforms like Telegram at prices as low as $120 for a 10-day phishing campaign.

To counteract threats like Tycoon 2FA, organizations must adopt layered security measures:-

  • Behavioral-based detection systems
  • Phishing-resistant MFA methods
  • Educate employees
  • Deploy advanced email filtering solutions

Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago