Tycoon 2FA Phishing Kit Targets M365 and Gmail Users

Tycoon 2FA Phishing Kit Targets M365 and Gmail Users

First seen 10 Nov 2025, 11:52 UTC CybereasonGbhackers 74% similarity 28.5

Article Content

Browse articles
ThreatCluster

The Tycoon 2FA phishing kit, a Phishing-as-a-Service platform, was designed to bypass two-factor authentication protections for Microsoft 365 and Gmail accounts. It utilizes an Adversary-in-the-Middle approach with a reverse proxy server to create deceptive phishing pages that capture user credentials and session cookies in real-time. This sophisticated tool emerged in August 2023 and continues to pose risks to users of these services.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story