Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Tycoon 2FA

2
Global rank
34 infographic chevron month
Month rank
40 infographic chevron week
Week rank
0
IOCs

Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.

Phishingkit
Type
Unknown
Origin
1 August, 2023
First seen
28 August, 2026
Last seen

How to analyze Tycoon 2FA with ANY.RUN

Type
Unknown
Origin
1 August, 2023
First seen
28 August, 2026
Last seen

IOCs

IP addresses
150.171.27.11
2.19.13.249
104.17.24.14
150.171.22.17
13.107.246.44
52.123.243.81
52.110.17.19
150.171.109.104
142.251.20.95
172.211.123.248
95.101.74.32
150.171.109.193
208.91.199.242
23.11.41.157
142.250.154.132
20.67.186.184
2.18.244.219
40.126.31.71
150.171.28.11
52.111.231.13
Hashes
0e60b52689f3627486b9a77bb4f88bea0d8665a94f7f1ffc960a1fbc427626b7
d1614ad99aded9f6f5c1be7fe7ffa5124bd04a526580da3818ea8a954e852aa6
895e6545b5a3e70f822b4f19e11117b7d6a3cdb2094ad60e2fe17d9f18ec3042
81ff65efc4487853bdb4625559e69ab44f19e0f5efbd6d5b2af5e3ab267c8e06
89c701eeff939a44f28921fd85365ecd87041935dcd0fe0baf04957da12c9899
b6b10a07faa634027f3780e77fc3b165dcf7d37e800195bff5e147ccc492b828
9867cd38dbcd58ea2759199eda7ac0fa47b070a76398890d7e05b5a7df9dc935
1bda750084f20306722008016420e1912ba608ca8efb9c661f7e7efcf5e89673
8013ac030684b86d754bbfbab8a9cec20caa4dd9c03022715ff353dc10e14031
73002d28d89721be4401474eee3e28cdf10aa006cfef5750ba4c3d920d198943
266da3069a00ae9193ac11ae63771f5aeefa18b1862a441e03d319fde7bc1680
a8caa227bb4d3f5f831ba8756cb24a675dc0a97043eeefbdc0fca0b47ff3dd69
15fe159b564d7aea28f48dcb0ad9d32863da9cbff6a9c9707e83f05c773e1155
8804d2766bdbe34b6d37ee6494630bdffa6263d7ecd7433a869f6110404e2c22
afd588d7d1c94d797ef932006d524de973f6fc54556e62f0f340412c87f99d58
51eb16447d65a8e85488cc5b300daa11092e03134afc7e587392a1563640ca8d
b58b77da7d6b8189a959a9003a2f3b2adef58b01d8bb1251c1361d843f3a1e6b
8e6db1634f1812d42516778fc890010aa57f3e39914fb4803df2c38abbf56d93
90cdaf487716184e4034000935c605d1633926d348116d198f355a98b8c6cd21
8737d721808655f37b333f08a90185699e7e8b9bdaaa15cdb63c8448b426f95d
Domains
www.microsoft.com
login.live.com
edge-consumer-static.azureedge.net
fe3cr.delivery.mp.microsoft.com
fonts.googleapis.com
fumaumb.com
slscr.update.microsoft.com
aadcdn.msauth.net
google.com
ocsp.digicert.com
oneocsp.microsoft.com
copilot.microsoft.com
settings-win.data.microsoft.com
www.bing.com
login.microsoftonline.com
xpaywalletcdn.azureedge.net
editor.svc.cloud.microsoft
ecs.office.com
coop.msauth.net
client.wns.windows.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://officeclient.microsoft.com/config16/?lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3
https://ecs.office.com/config/v2/office/outlook/16.0.16026.20146/production/cc?&clientid=%7bd61ab268-c26a-439d-bb15-2a0dedfca6a3%7d&application=outlook&platform=win32&version=16.0.16026.20146&msoversion=16.0.16026.20002&sdx=fa000000002.2.0.1907.31003&sdx=fa000000005.1.0.1909.30011&sdx=fa000000006.1.0.1909.13002&sdx=fa000000008.1.0.1908.16006&sdx=fa000000009.1.0.1908.6002&sdx=fa000000016.1.0.1810.13001&sdx=fa000000029.1.0.1906.25001&sdx=fa000000033.1.0.1908.24001&sdx=wa104381125.1.0.1810.9001&processname=outlook.exe&audience=production&build=ship&architecture=x64&language=en-us&subscriptionlicense=false&perpetuallicense=2019&licensecategory=6&licensesku=professional2019retail&osversion=10.0&osbuild=19045&channel=cc&installtype=c2r&sessionid=%7b1ee4e5fe-e056-4b49-8f7f-a941bb25b8d9%7d&labmachine=false
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://roaming.svc.cloud.microsoft/rs/roamingsoapservice.svc
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaale%2bvmfuqbvyaaaaaaaas%3d
https://omex.cdn.office.net/addinclassifier/officesharedentities
https://messaging.lifecycle.office.com/getcustommessage16?app=6&ui=en-us&src=bizbar&messagetype=bizbar&hwid=04111-083-043729&ver=16.0.16026&lc=en-us&platform=10%3a0%3a19045%3a2%3a0%3a0%3a256%3a1%3a&productid=%7b1717c1e0-47d3-4899-a6d3-1022db7415e0%7d%3a00411-10830-43729-aa720%3aoffice%2019%2c%20office19professional2019r_retail%20edition&clientsessionid=%7b1ee4e5fe-e056-4b49-8f7f-a941bb25b8d9%7d&datapropertybag=%7b%22audience%22%3a%22production%22%2c%22audiencegroup%22%3a%22production%22%2c%22audiencechannel%22%3a%22cc%22%2c%22flight%22%3a%22ofsh6c2b1tla1a31%2cofcrui4yvdulbf31%2cofhpex3jznepoo31%22%7d
https://editor.svc.cloud.microsoft/nleditor/cloudsuggest/v1
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://odc.officeapps.live.com/odc/servicemanager/catalog?lcid=1033&syslcid=1033&uilcid=1033&app=5&ver=16&schema=8
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaaoqpopjdxrqzsaaaaaaa4%3d
https://self.events.data.microsoft.com/onecollector/1.0/
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2800
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7890
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10855
comments 0

What is Tycoon 2FA?

This Adversary-in-the-Middle (AiTM) phishing kit became known in 2023, with significant updates observed through 2025. The PhaaS model allows even low-skilled attackers to deploy sophisticated phishing campaigns

Tycoon 2FA can intercept user credentials and session cookies to bypass MFA, enabling unauthorized access to accounts even with additional security measures. Organizations using cloud services are at the most risk.

The kit is distributed via Telegram channels starting at $120 for 10 days, with prices varying by domain extension (.com, .net, .org, etc.).

Tycoon 2FA has a multi-stage attack process through social engineering and compromised infrastructure, including phishing emails and QR codes; redirects to fake login pages; exploitation of legitimate services (e.g., Milanote for project collaboration).

Read detailed breakdown of Tycoon2FA’s defense evasion techniques

Victims are directed to a counterfeit login page mimicking Microsoft 365 or Gmail, where they unknowingly enter their credentials. A custom CAPTCHA (previously Cloudflare Turnstile, now HTML5 canvas-based) filters out automated bots and security tools, ensuring only human users proceed.

If MFA is enabled, Tycoon 2FA acts as a man-in-the-middle, relaying MFA prompts and capturing session cookies in real time upon successful authentication. These cookies grant attackers unauthorized access to the victim's account without needing further credentials. Attackers reuse session cookies to bypass security controls and access accounts even if credentials are reset.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Tycoon 2FA Prominent Features

  • MFA Bypass: By capturing session cookies, Tycoon 2FA renders traditional MFA (e.g., SMS, authenticator apps) ineffective, compromising even security-conscious organizations.
  • Targeted Attacks: Primarily targets Microsoft 365 and Gmail, critical for enterprise and cloud environments, leading to potential data breaches, financial loss, or ransomware deployment.
  • Ease of Use: As a PhaaS platform, it provides ready-to-use templates and admin panels, enabling even low-skilled attackers to launch sophisticated campaigns.
  • Longevity: Advanced evasion techniques allow campaigns to remain undetected longer, increasing the number of compromised accounts.
  • Exploitation of Legitimate Infrastructure: Using compromised legitimate accounts and services like Milanote enhances credibility and evades traditional email security filters.
  • Scalability: Over 1,200 domains associated with Tycoon 2FA were identified between August 2023 and February 2024, indicating widespread use.

Tycoon 2FA Execution Process and Technical Details

ANY.RUN’s Interactive Sandbox, trusted by over 500,000 threat analysts and 15,000 SOC teams, contains an impressive collection of malware samples featuring Tycoon 2FA attacks. Let’s scrutinize the phish kit’s strategy and tactics on an illustrative analysis session.

View the analysis and gather actionable data.

Tycoon 2FA analysis in ANY.RUN Sandbox Tycoon 2FA sample in ANY.RUN's Interactive Sandbox

The execution chain typically begins with phishing emails or QR codes that direct victims to malicious URLs. These messages often impersonate trusted services and may be sent via legitimate platforms to enhance credibility. When a victim clicks the link, they are redirected through several intermediate pages, including CAPTCHA challenges such as reCAPTCHA or Cloudflare CAPTCHA, which are used to block bots and avoid automated detection systems.

ANY.RUN supports Automated Interactivity (ML) capable of handling such challenges in submitted tasks, including those sent via API. These CAPTCHA steps also help attackers evade sandbox detection by filtering out non-human traffic. During this redirection process, the kit performs environment checks by analyzing IP addresses, user agents, and browser fingerprints to identify security researchers or automated tools. These detections are ineffective against ANY.RUN, which uses residential proxies to simulate legitimate user traffic. If suspicious activity is detected, the visitor is redirected to a benign website to avoid raising alarms.

After passing the environment checks, the victim is taken to a fake login page that closely imitates Microsoft 365 or Gmail authentication portals. These pages are tailored to match the victim’s organization by modifying branding elements using legitimate services. Built with obfuscated and randomized JavaScript and HTML, these pages are designed to evade detection by signature-based security tools.

When the victim submits their credentials and, if prompted, an MFA code, the phishing kit captures the information in real time and forwards it to the legitimate Microsoft or Gmail servers via a reverse proxy. This enables the attackers to intercept valid session cookies, effectively bypassing MFA. With these session tokens, attackers gain persistent, unauthorized access without needing to reauthenticate.

To complicate analysis, payloads and exfiltrated data are often encrypted using AES, while URLs are randomized and malicious resources are delayed until after CAPTCHA completion to avoid detection by automated scanners.

What are the best-known Tycoon 2FA attacks?

  • Initial Emergence (August 2023): Identified by Sekoia, targeted Microsoft 365 with AiTM phishing, used phishing emails and Cloudflare Turnstile CAPTCHAs, compromised enterprise accounts.
  • Campaign Expansion (October 2023 - February 2024): Over 3,000 phishing pages, targeted Microsoft 365 and Gmail, used QR codes and Milanote, employed invisible Unicode obfuscation, caused widespread credential theft.
  • Custom CAPTCHA Evolution (Mid-2024): Shifted to HTML5 canvas-based CAPTCHA, added anti-debugging scripts and malformed URLs, prolonged campaign lifespans, targeted corporate accounts.
  • Advanced Obfuscation (April-May 2025): Added browser fingerprinting and payload encryption, rejected Tor/scanner traffic, disabled context menus, increased MFA bypass success.
  • Common Traits: PhaaS sold via Telegram for $120+, bypassed MFA via session cookie theft, targeted Microsoft 365/Gmail, used legitimate services, linked to 1,200+ domains.
  • Impacts: Hit financial sector for fraud, enabled enterprise breaches and ransomware, used stolen credentials for BEC.
  • Detection Challenges: Evaded detection with Unicode obfuscation, custom CAPTCHAs, and dynamic code; no specific threat actor, linked to Saad Tycoon Group.

Gathering Threat Intelligence on Tycoon 2FA Phish Kit

To counter Tycoon 2FA, organizations should adopt a proactive, multi-layered defense strategy informed by threat intelligence. Solutions like ANY.RUN’s Threat Intelligence Lookup help to detect and block known Tycoon 2FA infrastructure like domains and IPs at the network edge.

Make an easy entrance to Tycoon 2FA investigation by searching the threat by the name via TI Lookup. View any analysis session to get acquainted with the phish kit operators’ TTPs and gather indicators of compromise to set up alerts and defenses.

threatName:"tycoon"

Tycoon 2FA samples Sandbox malware analyses featuring Tycoon 2FA

Tycoon 2FA IOCs in Sandbox Tycoon 2FA IOCs extracted from a malware sample

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Tycoon 2FA is an evolved phishing kit that poses a significant threat due to its ability to bypass MFA, leverage legitimate infrastructure, and employ advanced evasion techniques like invisible Unicode obfuscation, custom CAPTCHAs, and anti-debugging scripts. Its ease of use and scalability make it accessible to a wide range of cybercriminals, amplifying its impact.

Detection and counteraction require a combination of behavioral monitoring, advanced threat intelligence, phish-resistant MFA, and user awareness.

Use Threat Intelligence Lookup to shoot Tycoon 2FA on approach: start with 50 trial searches.

HAVE A LOOK AT

LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
SnappyClient screenshot
SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.
Read More
WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
Emmenhtal screenshot
Emmenhtal
emmenhtal
First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments.
Read More