Cybercriminals have been increasingly using a new phishing-as-a-service (PhaaS) platform named 'Tycoon 2FA' to target Microsoft 365 and Gmail accounts and bypass two-factor authentication (2FA) protection. Tycoon 2FA was discovered by Sekoia analysts in October 2023 during routine threat hunting, but it has been active since at least August 2023, when the Saad Tycoon group offered it through private Telegram channels. The PhaaS kit shares similarities with other adversary-in-the-middle (AitM) platforms, such as Dadsec OTT, suggesting possible code reuse or a collaboration between developers. In 2024, Tycoon 2FA released a new version that is stealthier, indicating a continuous effort to improve the kit. Currently, the service leverages 1,100 domains and has been observed in thousands of phishing attacks. Tycoon 2FA attacks involve a multi-step process where the threat actor steals session cookies by using a reverse proxy server hosting the phishing web page, which intercepts the victim's input and relays them to the legitimate service. "Once the user completes the MFA challenge, and the authentication is successful, the server in the middle captures session cookies," Skoia explains. This way, the attacker can replay a user's session and bypass multi-factor authentication (MFA) mechanisms. Sekoia's report describes the attacks in seven distinct stages as described below: An overview of the attack is described with the diagram below, which includes all the steps of the process...
New MFA-bypassing phishing kit targets Microsoft 365, Gmail accounts
BleepingComputer
·Bill Toulas
·Published Mar 25, 2024
·Updated
Affected Software
2 affected components
Microsoft Microsoft 365
Google Gmail
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new phishing kit called 'Tycoon 2FA' that targets Microsoft 365 and Gmail accounts to bypass two-factor authentication.
2
What security implications are discussed?
The article highlights the dangers of MFA bypassing techniques that can compromise user accounts despite having two-factor authentication enabled.
3
What products or software are affected?
The affected products include Microsoft 365 and Gmail accounts.
4
How does the Tycoon 2FA phishing kit work?
The Tycoon 2FA phishing kit functions by simulating legitimate login pages to trick users into submitting their credentials and bypassing MFA.
5
Who is likely to be targeted by this phishing kit?
Users of Microsoft 365 and Gmail accounts are the primary targets of the Tycoon 2FA phishing kit.