Close Menu
    What's Hot

    World Matchplay Darts: Luke Humphries shocked by Cameron Menzies in first round at the Winter Gardens in Blackpool | Darts News

    Faced With Piles of New Paperwork, People Are Losing Food Stamps

    Will a Sex Scandal Involving Mark Lamb Matter in Arizona GOP House Primary?

    Facebook X (Twitter) Instagram
    Trending
    • World Matchplay Darts: Luke Humphries shocked by Cameron Menzies in first round at the Winter Gardens in Blackpool | Darts News
    • Faced With Piles of New Paperwork, People Are Losing Food Stamps
    • Will a Sex Scandal Involving Mark Lamb Matter in Arizona GOP House Primary?
    • The Galaxy Card Is Samsung’s Answer to the Apple Card
    • GameStop’s eBay Deal Is Less An Acquisition Than An Activist Play (NYSE:GME)
    • Mythos Didn’t Break Your Security Program. Your Exposure Window Could.
    • Trump photobombing historical photos becomes a meme after an awkward moment at the World Cup final
    • Iran War Live Updates: Iranian -Backed Houthis Expand Conflict With Red Sea Blockade
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks

    adminBy adminMarch 5, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks

    Tycoon 2FA, one of the prominent phishing-as-a-service (PhaaS) toolkits that allowed cybercriminals to stage adversary-in-the-middle (AitM) credential harvesting attacks at scale, was dismantled by a coalition of law enforcement agencies and security companies.

    The subscription-based phishing kit, which first emerged in August 2023, was described by Europol as one of the largest phishing operations worldwide. The kit was available for a starting price of $120 for 10 days or $350 for access to a web-based administration panel for a month.

    The panel serves as a hub for configuring, tracking, and refining campaigns. It features pre‑built templates, attachment files for common lure formats, domain and hosting configuration, redirect logic, and victim tracking. Operators can also configure how the malicious content is delivered through attachments, as well as keep tabs on valid and invalid sign-in attempts.

    The captured information, such as credentials, multi-factor authentication (MFA) codes, and session cookies, can be downloaded directly within the panel or forwarded to Telegram for near‑real‑time monitoring.

    Cybersecurity

    “It enabled thousands of cybercriminals to covertly access email and cloud-based service accounts,” Europol said. “At scale, the platform generated tens of millions of phishing emails each month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions.”

    As part of the coordinated effort, 330 domains that formed the backbone of the criminal service, including phishing pages and control panels, have been taken down.

    Characterizing Tycoon 2FA as “dangerous,” Intel 471 said the kit was linked to over 64,000 phishing incidents and tens of thousands of domains, generating tens of millions of phishing emails each month. According to Microsoft, which is tracking the operators of the service under the name Storm-1747, Tycoon 2FA became the most prolific platform observed by the company in 2025, blocking more than 13 million malicious emails linked to the crimeware service.

    Tycoon 2FA Evolution Timeline (Source: Point Wild)

    Data from Proofpoint shows that Tycoon 2FA accounted for the highest volume AiTM phishing threats. The email security company said it observed over three million messages associated with the phishing kit in February 2026 alone. Trend Micro, which was one of the private sector partners in the operation, noted that the PhaaS platform had approximately 2,000 users.

    Campaigns leveraging Tycoon 2FA have indiscriminately targeted almost all sectors, including education, healthcare, finance, non-profit, and government. Phishing emails sent from the kit reached over 500,000 organizations each month worldwide. 

    “Tycoon 2FA’s platform enabled threat actors to impersonate trusted brands by mimicking sign-in pages for services like Microsoft 365, OneDrive, Outlook, SharePoint, and Gmail,” Microsoft said. 

    “It also allowed threat actors using its service to establish persistence and to access sensitive information even after passwords are reset, unless active sessions and tokens were explicitly revoked. This worked by intercepting session cookies generated during the authentication process, simultaneously capturing user credentials. The MFA codes were subsequently relayed through Tycoon 2FA’s proxy servers to the authenticating service.”

    The kit also employed techniques like keystroke monitoring, anti-bot screening, browser fingerprinting, heavy code obfuscation, self-hosted CAPTCHAs, custom JavaScript, and dynamic decoy pages to sidestep detection efforts. Another key aspect is the use of a broader mix of top-level domains (TLDs) and short-lived fully qualified domain names (FQDNs) to host the phishing infrastructure on Cloudflare.

    Cybersecurity

    The FQDNs often only last for 24 to 72 hours, with the rapid turnover a deliberate effort to complicate detection and prevent building reliable blocklists. Microsoft also attributed Tycoon 2FA’s success to closely mimicking legitimate authentication processes to stealthily intercept user credentials and session tokens.

    To make matters worse, Tycoon 2FA customers leveraged a technique called ATO Jumping, whereby a compromised email account is used to distribute Tycoon 2FA URLs and attempt further account takeover activities. “Using this technique enables emails to look like they are authentically coming from a victim’s trusted contact, increasing the likelihood of a successful compromise,” Proofpoint noted.

    Phishing kits like Tycoon are designed to be flexible so that it’s accessible to less technically savvy actors while still offering advanced capabilities for more experienced operators.

    “In 2025, 99% of organizations experienced account takeover attempts in 2025, and 67% experienced a successful account takeover,” Selena Larson, staff threat researcher at Proofpoint, said in a statement shared with The Hacker News. “Of these, 59% of the taken-over accounts had MFA enabled. While not all of these attacks were related to Tycoon MFA, this shows the impact of AiTM phishing on enterprises.”

    “These cyberattacks that enable full account takeovers can lead to disastrous impacts, including ransomware or the loss of sensitive data. As threat actors continue to prioritize identity, gaining access to enterprise email accounts is often the first step in an attack chain that can have destructive consequences.”

    2FA Attacks EuropolLed linked operation PhishingasaService takes Tycoon
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticlePlanning Travel Around These Things Will Transform the…
    Next Article Bill Gates-backed TerraPower begins nuclear reactor construction
    admin
    • Website

    Related Posts

    Mythos Didn’t Break Your Security Program. Your Exposure Window Could.

    July 20, 2026

    FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

    July 20, 2026

    Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

    July 20, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    World Matchplay Darts: Luke Humphries shocked by Cameron Menzies in first round at the Winter Gardens in Blackpool | Darts News

    Faced With Piles of New Paperwork, People Are Losing Food Stamps

    Will a Sex Scandal Involving Mark Lamb Matter in Arizona GOP House Primary?

    The Galaxy Card Is Samsung’s Answer to the Apple Card

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by