Tycoon2FA is a malware family tracked across 11 threat clusters and 18 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity March 13, 2026.
On March 3 and 4, 2026, a coordinated international law enforcement operation led by the FBI and Europol resulted in the seizure of LeakBase, one of the largest online forums for cybercriminals, which had over 142,000…
A coordinated international effort led by Microsoft and Europol has dismantled Tycoon2FA, a significant phishing-as-a-service platform responsible for bypassing multi-factor authentication and enabling large-scale…
An international cybercrime operation, Operation Synergia III, coordinated by INTERPOL, has dismantled over 45,000 malicious IP addresses and servers linked to phishing, malware, and ransomware attacks. The operation,…
The Sneaky2FA phishing-as-a-service kit has integrated Browser-in-the-Browser (BITB) techniques to enhance its ability to steal Microsoft 365 credentials. This updated functionality allows attackers to create deceptive…
A phishing automation platform named Quantum Route Redirect has been identified, utilizing around 1,000 domains to steal Microsoft 365 user credentials. Discovered by KnowBe4 in August, this platform allows less skilled…
eSentire reported a significant rise in account compromises in 2025, with email-led intrusions linked to credential theft. The research, based on data from over 2,000 customers, indicated that account compromise…
ANY.RUN has published its 2025 Year in Review report, detailing significant growth and breakthroughs in malware analysis and threat intelligence. The report reflects contributions from a global community of 15,000 SOC…
The Sneaky2FA phishing-as-a-service kit has been upgraded to include Browser-in-the-Browser (BITB) techniques, allowing attackers to create deceptive phishing pages that mimic legitimate login interfaces. This evolution…
Attackers are exploiting misconfigured email routing to spoof internal emails, utilizing PhaaS platforms like Tycoon2FA to steal credentials. This tactic allows phishing actors to bypass spoof protections and send…
The Quantum Route Redirect phishing-as-a-service platform is exploiting nearly 1,000 domains to steal Microsoft 365 user credentials. Discovered by KnowBe4 in August 2025, this platform automates phishing attacks,…