Skip to content
Tycoon 2FA Phishing Kit Targets M365 and Gmail Users

Tycoon 2FA Phishing Kit Targets M365 and Gmail Users

First seen 10 Nov 2025, 11:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The Tycoon 2FA phishing kit, a Phishing-as-a-Service platform, was designed to bypass two-factor authentication protections for Microsoft 365 and Gmail accounts. It utilizes an Adversary-in-the-Middle approach with a reverse proxy server to create deceptive phishing pages that capture user credentials and session cookies in real-time. This sophisticated tool emerged in August 2023 and continues to pose risks to users of these services.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (2)