• News/
  • https://www.bleepingcomputer.com/news/security/new-mfa-bypassing-phishing-kit-targets-microsoft-365-gmail-accounts/

New MFA-bypassing phishing kit targets Microsoft 365, Gmail accounts

BleepingComputer
·
Bill Toulas
·
Published Mar 25, 2024
·
Updated

Cybercriminals have been increasingly using a new phishing-as-a-service (PhaaS) platform named 'Tycoon 2FA' to target Microsoft 365 and Gmail accounts and bypass two-factor authentication (2FA) protection. Tycoon 2FA was discovered by Sekoia analysts in October 2023 during routine threat hunting, but it has been active since at least August 2023, when the Saad Tycoon group offered it through private Telegram channels. The PhaaS kit shares similarities with other adversary-in-the-middle (AitM) platforms, such as Dadsec OTT, suggesting possible code reuse or a collaboration between developers. In 2024, Tycoon 2FA released a new version that is stealthier, indicating a continuous effort to improve the kit. Currently, the service leverages 1,100 domains and has been observed in thousands of phishing attacks. Tycoon 2FA attacks involve a multi-step process where the threat actor steals session cookies by using a reverse proxy server hosting the phishing web page, which intercepts the victim's input and relays them to the legitimate service. "Once the user completes the MFA challenge, and the authentication is successful, the server in the middle captures session cookies," Skoia explains. This way, the attacker can replay a user's session and bypass multi-factor authentication (MFA) mechanisms. Sekoia's report describes the attacks in seven distinct stages as described below: An overview of the attack is described with the diagram below, which includes all the steps of the process...

Read full article

Affected Software

2 affected components
Microsoft Microsoft 365
Google Gmail
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new phishing kit called 'Tycoon 2FA' that targets Microsoft 365 and Gmail accounts to bypass two-factor authentication.

2

What security implications are discussed?

The article highlights the dangers of MFA bypassing techniques that can compromise user accounts despite having two-factor authentication enabled.

3

What products or software are affected?

The affected products include Microsoft 365 and Gmail accounts.

4

How does the Tycoon 2FA phishing kit work?

The Tycoon 2FA phishing kit functions by simulating legitimate login pages to trick users into submitting their credentials and bypassing MFA.

5

Who is likely to be targeted by this phishing kit?

Users of Microsoft 365 and Gmail accounts are the primary targets of the Tycoon 2FA phishing kit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203