Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Tycoon 2FA

4
Global rank
52 infographic chevron month
Month rank
66 infographic chevron week
Week rank

Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.

Phishingkit
Type
Unknown
Origin
1 August, 2023
First seen
17 September, 2026
Last seen

How to analyze Tycoon 2FA with ANY.RUN

Type
Unknown
Origin
1 August, 2023
First seen
17 September, 2026
Last seen

IOCs

IP addresses
2.23.246.9
142.251.20.113
34.54.185.247
157.240.253.35
172.217.113.4
57.144.248.128
142.251.20.139
199.232.214.172
142.251.127.84
172.217.112.4
52.110.17.61
104.18.10.207
176.96.129.3
142.251.14.97
2.22.50.149
142.251.14.100
172.217.208.95
151.101.1.91
23.11.41.157
184.31.95.119
Hashes
22a22e76f4de930e54dd33af00c71b68828847409e5e79787df5224dd9776c6f
0b5c5ec0a94bc19f8208842d8eb29be8c22fd9fd5dbdb0a55b5aaa0acd7a8b20
c33b23c46829d349f7211c9dbc29a67f501c7e4742d6a682e1a2b88bae31ab3d
38f887aae5817d39b1e55cd669d4387433f02da1806297bce53ec18fa0a565d1
2712f5173c2f959d1a9fad564337e642911277a50abc25f9b16e8a7ddd4e9c89
96a89d1035dae125d63cc2fab1e418c3bc770c9619c6350462d86c457c0a8fd7
2ffd63b17fe8d301c7babc15b827bec99f65ccbbb62151933754e8429a215d17
2c2c64178dbd56cf5a09fa9c2dd10aa1c9dc57a3f847cb43315c84aeb235e3bd
5219a6da97df5b3c5e95f53cccd95eb48eaa8e99859e1ef7b038d3240f6567ac
20f3e4827fccb97987b1a696c86c1ead82007d0b593b8b6aa949a9b91bf684df
9760b02c550cef41040ce62c54dc22c77cecb935577f47b3a020e00a6a888e9f
f9dddc331cfe02ccd42940b718efd0658e7a6f4695d720a347a1f89ba901d2f0
e385bd6e4f9fdb13d7b2dc895270356c86ff03ef5a8c8cbcfcdc5e2ea530ac00
eaea1c7eeb2af4fcb59c7db541df61057c4ccdb8a4d4f70af75776d70aa1850c
b1e963d702392fb7224786e7d56d43973e9b9efd1b89c17814d7c558ffc0cdec
8d21fe1bd251856bfaeaedd6a72ab78f153a047b6042e0fc614f57a32b56d340
f36e9baeb8e56b8d34d4833caf25cd28d2b4be214016dc068abfff3535c11635
a0956386dc64fd9f4883c8741f950cd60a56859616b159c9e4251c9eb0ac5534
3c88fd9805746be38b8d567b81dccee7c790ed17ca58902e69506b1e4c41fd3f
f3d6e0446e4eb9dcbde624a799bbe66ca89d30fddc51a34de5ce5e89cfa300b5
Domains
clientservices.googleapis.com
www.google.com
safebrowsingohttpgateway.googleapis.com
ecs.office.com
static.xx.fbcdn.net
google-ohttp-relay-safebrowsing.fastly-edge.com
update.googleapis.com
www.google-analytics.com
gundemekonometre.com
analyticsnode.xyz
eip-terr-eu.cdp1.digicert.com.akahost.net
prod.ingestion-edge.prod.dataservices.mozgcp.net
login.live.com
www.googletagmanager.com
google.com
translate.googleapis.com
officeclient.microsoft.com
scontent-lga3-1.xx.fbcdn.net
maxcdn.bootstrapcdn.com
mrodevicemgr.officeapps.live.com
URLs
http://ocsp.digicert.com/
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b9f8bdeace748b45
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f54766160ceeeba8
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbsnxliz3fu1wb6n1%2fe6xwn1b0jxiqqudiwawgbh3zfez70pn6odhb7tzrccealxhnr4eln54rgipwq89vq%3d
http://clients2.google.com/time/1/current?cup2key=8:aijwti-askutq7rvb4hy1mxnwru3qxpte78kuok3p0w&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://gundemekonometre.com/
http://www.msftconnecttest.com/connecttest.txt
https://ecs.office.com/config/v2/office/officeclicktorun/16.0.16626.20134/production/cc?&clientid=%7b80c2a92b-edee-479e-8470-dbc6c547f2fb%7d&application=officeclicktorun&platform=win32&version=16.0.16626.20134&msoversion=16.0.16626.20134&processname=officec2rclient.exe&audience=production&build=ship&architecture=x64&osversion=10.0&osbuild=22000&channel=cc&installtype=c2r&sessionid=%7b99261673-9f22-4e52-96db-4b80fc8681bb%7d&labmachine=false
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://google-ohttp-relay-safebrowsing.fastly-edge.com/
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=134
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://safebrowsing.googleapis.com/v4/fullhashes:find?$req=ch0kdgdvb2dszwnocm9tzrinmtm0ljaunjk5oc4znhibcg0ibraggaeiazawmtabenxtgbocgaoiezy1ehokdqgqeayyasidmdaxmaeq8icaahgdbuuklbibcg0iaraggaeiazawmtabeo2bdxocgapavyeoehskdqgdeayyasidmdaxmaeqmjmpggiya-zyo2ssgwonca4qbhgbigmwmdewardlzacaahgdjbsyfribcg0ibxaggaeiazawmtabeprhdxocgaoctiihehokdqgbeagyasidmdaxmaqq0zoaahgdmny8nxibcg0idxaggaeiazawmtabeibbaxocgapykqtfehkkdqgjeayyasidmdaxmaeqixocgapgc7ipehokdqgieayyasidmdaxmaeq4byaahgdpbveqbibcg0idraggaeiazawmtabeimtahocgapdrhfmgiyiaqgdcauibgghcagicqgnca4idwgqeaeqcbogcgsgm0jhiaegba==&$ct=application/x-protobuf&key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://gundemekonometre.com/
https://mrodevicemgr.officeapps.live.com/mrodevicemgrsvc/api/v1/c2rtargetaudiencedata?omid=97560490bafb0d49bca6f8f0df91025d&susid=c408ee57-2103-4c34-9e6f-30bdf6c87e50&audienceffn=492350f6-3a01-4f97-b9c0-c7c6ddf67d60&tid=&osver=client%7c10.0.22000&offver=16.0.16626.20134&ring=production&aud=production&ch=cc&osarch=x64&manstate=6
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ea60f2ad792b2edc
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.22000.795.amd64fre.co_release.210604-1628&localdeviceid=s%3adacd04bd-5869-44da-9fd2-107288ff2e26&flightring=retail&attrdataver=183&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css
https://gundemekonometre.com/css/tema.css.php
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 854
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1130
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 2744
comments 0

What is Tycoon 2FA?

This Adversary-in-the-Middle (AiTM) phishing kit became known in 2023, with significant updates observed through 2025. The PhaaS model allows even low-skilled attackers to deploy sophisticated phishing campaigns

Tycoon 2FA can intercept user credentials and session cookies to bypass MFA, enabling unauthorized access to accounts even with additional security measures. Organizations using cloud services are at the most risk.

The kit is distributed via Telegram channels starting at $120 for 10 days, with prices varying by domain extension (.com, .net, .org, etc.).

Tycoon 2FA has a multi-stage attack process through social engineering and compromised infrastructure, including phishing emails and QR codes; redirects to fake login pages; exploitation of legitimate services (e.g., Milanote for project collaboration).

Read detailed breakdown of Tycoon2FA’s defense evasion techniques

Victims are directed to a counterfeit login page mimicking Microsoft 365 or Gmail, where they unknowingly enter their credentials. A custom CAPTCHA (previously Cloudflare Turnstile, now HTML5 canvas-based) filters out automated bots and security tools, ensuring only human users proceed.

If MFA is enabled, Tycoon 2FA acts as a man-in-the-middle, relaying MFA prompts and capturing session cookies in real time upon successful authentication. These cookies grant attackers unauthorized access to the victim's account without needing further credentials. Attackers reuse session cookies to bypass security controls and access accounts even if credentials are reset.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Tycoon 2FA Prominent Features

  • MFA Bypass: By capturing session cookies, Tycoon 2FA renders traditional MFA (e.g., SMS, authenticator apps) ineffective, compromising even security-conscious organizations.
  • Targeted Attacks: Primarily targets Microsoft 365 and Gmail, critical for enterprise and cloud environments, leading to potential data breaches, financial loss, or ransomware deployment.
  • Ease of Use: As a PhaaS platform, it provides ready-to-use templates and admin panels, enabling even low-skilled attackers to launch sophisticated campaigns.
  • Longevity: Advanced evasion techniques allow campaigns to remain undetected longer, increasing the number of compromised accounts.
  • Exploitation of Legitimate Infrastructure: Using compromised legitimate accounts and services like Milanote enhances credibility and evades traditional email security filters.
  • Scalability: Over 1,200 domains associated with Tycoon 2FA were identified between August 2023 and February 2024, indicating widespread use.

Tycoon 2FA Execution Process and Technical Details

ANY.RUN’s Interactive Sandbox, trusted by over 500,000 threat analysts and 15,000 SOC teams, contains an impressive collection of malware samples featuring Tycoon 2FA attacks. Let’s scrutinize the phish kit’s strategy and tactics on an illustrative analysis session.

View the analysis and gather actionable data.

Tycoon 2FA analysis in ANY.RUN Sandbox Tycoon 2FA sample in ANY.RUN's Interactive Sandbox

The execution chain typically begins with phishing emails or QR codes that direct victims to malicious URLs. These messages often impersonate trusted services and may be sent via legitimate platforms to enhance credibility. When a victim clicks the link, they are redirected through several intermediate pages, including CAPTCHA challenges such as reCAPTCHA or Cloudflare CAPTCHA, which are used to block bots and avoid automated detection systems.

ANY.RUN supports Automated Interactivity (ML) capable of handling such challenges in submitted tasks, including those sent via API. These CAPTCHA steps also help attackers evade sandbox detection by filtering out non-human traffic. During this redirection process, the kit performs environment checks by analyzing IP addresses, user agents, and browser fingerprints to identify security researchers or automated tools. These detections are ineffective against ANY.RUN, which uses residential proxies to simulate legitimate user traffic. If suspicious activity is detected, the visitor is redirected to a benign website to avoid raising alarms.

After passing the environment checks, the victim is taken to a fake login page that closely imitates Microsoft 365 or Gmail authentication portals. These pages are tailored to match the victim’s organization by modifying branding elements using legitimate services. Built with obfuscated and randomized JavaScript and HTML, these pages are designed to evade detection by signature-based security tools.

When the victim submits their credentials and, if prompted, an MFA code, the phishing kit captures the information in real time and forwards it to the legitimate Microsoft or Gmail servers via a reverse proxy. This enables the attackers to intercept valid session cookies, effectively bypassing MFA. With these session tokens, attackers gain persistent, unauthorized access without needing to reauthenticate.

To complicate analysis, payloads and exfiltrated data are often encrypted using AES, while URLs are randomized and malicious resources are delayed until after CAPTCHA completion to avoid detection by automated scanners.

What are the best-known Tycoon 2FA attacks?

  • Initial Emergence (August 2023): Identified by Sekoia, targeted Microsoft 365 with AiTM phishing, used phishing emails and Cloudflare Turnstile CAPTCHAs, compromised enterprise accounts.
  • Campaign Expansion (October 2023 - February 2024): Over 3,000 phishing pages, targeted Microsoft 365 and Gmail, used QR codes and Milanote, employed invisible Unicode obfuscation, caused widespread credential theft.
  • Custom CAPTCHA Evolution (Mid-2024): Shifted to HTML5 canvas-based CAPTCHA, added anti-debugging scripts and malformed URLs, prolonged campaign lifespans, targeted corporate accounts.
  • Advanced Obfuscation (April-May 2025): Added browser fingerprinting and payload encryption, rejected Tor/scanner traffic, disabled context menus, increased MFA bypass success.
  • Common Traits: PhaaS sold via Telegram for $120+, bypassed MFA via session cookie theft, targeted Microsoft 365/Gmail, used legitimate services, linked to 1,200+ domains.
  • Impacts: Hit financial sector for fraud, enabled enterprise breaches and ransomware, used stolen credentials for BEC.
  • Detection Challenges: Evaded detection with Unicode obfuscation, custom CAPTCHAs, and dynamic code; no specific threat actor, linked to Saad Tycoon Group.

Gathering Threat Intelligence on Tycoon 2FA Phish Kit

To counter Tycoon 2FA, organizations should adopt a proactive, multi-layered defense strategy informed by threat intelligence. Solutions like ANY.RUN’s Threat Intelligence Lookup help to detect and block known Tycoon 2FA infrastructure like domains and IPs at the network edge.

Make an easy entrance to Tycoon 2FA investigation by searching the threat by the name via TI Lookup. View any analysis session to get acquainted with the phish kit operators’ TTPs and gather indicators of compromise to set up alerts and defenses.

threatName:"tycoon"

Tycoon 2FA samples Sandbox malware analyses featuring Tycoon 2FA

Tycoon 2FA IOCs in Sandbox Tycoon 2FA IOCs extracted from a malware sample

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Tycoon 2FA is an evolved phishing kit that poses a significant threat due to its ability to bypass MFA, leverage legitimate infrastructure, and employ advanced evasion techniques like invisible Unicode obfuscation, custom CAPTCHAs, and anti-debugging scripts. Its ease of use and scalability make it accessible to a wide range of cybercriminals, amplifying its impact.

Detection and counteraction require a combination of behavioral monitoring, advanced threat intelligence, phish-resistant MFA, and user awareness.

Use Threat Intelligence Lookup to shoot Tycoon 2FA on approach: start with 50 trial searches.

HAVE A LOOK AT

Wshrat screenshot
Wshrat
wshrat rat trojan
WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
Oblivion RAT screenshot
Oblivion RAT
oblivion
Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.
Read More
Mispadu screenshot
Mispadu is a Windows banking trojan known for targeting online banking credentials, cryptocurrency wallets, and sensitive financial information. First identified in Latin America, the malware has continuously evolved with improved evasion techniques, phishing campaigns, and credential theft capabilities. Its reliance on social engineering rather than software vulnerabilities makes it an enduring threat to organizations whose employees interact with financial services online.
Read More
Keylogger screenshot
Keylogger
keylogger
A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.
Read More