Europol and Microsoft hit Tycoon 2FA with a typhoon of takedowns

Authentication workflows are a favourite target for attackers, and I’m sure I don’t need to explain why. Understanding how is important, though, and that explanation often starts with a phishing campaign.

Just this week, Microsoft issued a warning that threat actors are using this tactic to exploit legitimate OAuth authentication flows to redirect users to malicious sites. “This is a hard one to defend against,” said Michael Bell, Founder & CEO of Suzu Labs, “because the phishing links are routing through legitimate Microsoft and Google login pages, which means they pass URL filtering and browser security checks that most organisations rely on.”

The emergence of phishing-as-a-service kits, such as Spiderman, make it easy for attackers to launch campaigns that ultimately steal 2FA credentials.

I wrote about some of the biggest players in this attack space in January, but a lot has changed since then. Not least regarding Tycoon 2FA, which I said at the time was a major player that has continued to evolve its platform,  and continued to thrive in an increasingly cutthroat business.

But not anymore, I hope, following a confirmed operation coordinated by Europol’s European Cybercrime Centre. “As part of the disruption, 330 domains forming the core infrastructure of the criminal service, including phishing pages and control panels, were taken down,” Europol said in a statement.

And, to tie back into the OAuth attacks mentioned earlier, Microsoft was at the heart of the disruption. Microsoft led the technical disruption with the support of a coalition of private partners.

“Taking this infrastructure offline cuts off a major pipeline for account takeovers and helps protect people and organizations from follow‑on attacks such as data theft, ransomware, business email compromise, and financial fraud,” said Steven Masada, Assistant General Counsel, Microsoft’s Digital Crimes Unit.

Tycoon 2FA: a persistent threat

This is big news in terms of the criminal marketplace, despite Tycoon 2FA being far from a new threat.

It first came onto my radar in 2023, though it has ramped up its attacks and technical sophistication considerably since then. As far as so-called adversary-in-the-middle attack kits are concerned, this player was at the top of the pile.

“Taking down infrastructure associated with Tycoon 2FA and identifying the individual allegedly responsible for creating this prolific hacking tool will have a significant impact on overall MFA credential phishing and hopefully strike a blow to the world’s most prolific AiTM phishing-as-a-service,” said Selena Larson, a Staff Threat Researcher at Proofpoint, which took part in operational support.

What it isn’t, sadly, is a full stop. As we know only too well from ransomware group disruptions, when one is taken down, two or three others fight to fill the gap.

Security teams need to stay on top of the threat, and that means employing behaviour-based monitoring together with browser sandboxing.

“To stay protected,” Ashok Sakthivel, Director of Software Engineering at Barracuda, previously told TechFinitive, “organisations need to move past static defences and adopt layered strategies: user training, phishing-resistant MFA, continuous monitoring, and to ensure email security sits at the heart of an integrated, end-to-end security strategy.”

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.