CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 616

As cited

Copy frozen at (site build).

threat intel

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

Tycoon 2FA is a prolific phishing-as-a-service platform that performs adversary-in-the-middle attacks to bypass multi-factor authentication and steal authenticated session tokens from Microsoft 365 and Google Workspace. The kit operates as a reverse proxy that captures real-time authentication flows, including MFA challenges, and intercepts post-MFA session tokens before they reach the victim's browser. Despite a March 2026 takedown that seized over 300 domains, operators have adapted and continue deploying variants that use WebSocket-based proxying and OAuth device code abuse, employing sophisticated evasion techniques to avoid researcher detection.

Why it matters: Microsoft 365 and Google Workspace administrators and security teams need to detect and block Tycoon 2FA campaigns immediately, as the kit bypasses standard MFA protections and remains the top malware trend; organizations should implement conditional access policies, detect unusual token usage patterns, and monitor for phishing emails with embedded attachments containing login replicas.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

Tycoon 2FA, a Phishing-as-a-Service platform attributed to Storm-1747, enables adversary-in-the-middle attacks that bypass multi-factor authentication by stealing session tokens from Microsoft 365 and Google Workspace. Despite a March 2026 takedown, operators resumed campaigns by late April 2026, using WebSocket proxies and OAuth device code flows. The kit employs evasion techniques such as IP filtering, bot detection, and DevTools blocking to hinder analysis.

Why it matters: Microsoft 365 and Google Workspace users are exposed to ongoing credential and session token theft, requiring immediate review of authentication logs and phishing defenses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

Tycoon 2FA, a Phishing-as-a-Service platform attributed to Storm-1747, enables adversary-in-the-middle attacks that bypass multi-factor authentication by stealing session tokens from Microsoft 365 and Google Workspace. Despite a March 2026 takedown, operators resumed campaigns by late April 2026, using WebSocket proxies and OAuth device code flows. The kit employs evasion techniques such as IP filtering, bot detection, and DevTools blocking to hinder analysis.

Why it matters: Microsoft 365 and Google Workspace users are exposed to ongoing credential and session token theft, requiring immediate review of authentication logs and phishing defenses.

VendorsMicrosoftAppleGoogleCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary