Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
Tycoon2FA has shifted from a subscription-based PhaaS and AitM credential harvester into a more resilient campaign that now uses device-code phishing against Microsoft 365 accounts. After an international law-enforcement operation in March that removed 330 domains and was tied to over 64,000 phishing incidents, the service rebuilt and by late April was again being used in campaigns abusing the OAuth 2.0 device authorization grant. In the latest reporting, eSentire says invoice-themed lure emails with Trustifi click-tracking URLs route victims through Trustifi, Cloudflare Workers, obfuscated JavaScript, and a fake Microsoft CAPTCHA page before reaching microsoft.com/devicelogin. The kit also added stronger anti-analysis controls, including checks for Selenium, Puppeteer, Playwright, and Burp Suite, plus a 230-vendor blocklist.
Related Happenings
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
Campaign
H score37
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
CampaignAbout this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
ShinyHunters-linked Salesforce intrusion campaign
Campaign
H score45
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
ShinyHunters-linked Salesforce intrusion campaign
CampaignAbout this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Timeline
-
17.05.2026 17:43 1 articles · 1mo ago
Tycoon2FA adds device-code phishing against Microsoft 365
Technical Analysis UpdateeSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Show sources
- Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing — www.bleepingcomputer.com — 17.05.2026 17:43
-
05.03.2026 08:51 2 articles · 4mo ago
Europol-led takedown dismantles Tycoon 2FA
Legal Policy Action UpdateEuropol and private-sector partners dismantled Tycoon 2FA, a subscription-based phishing-as-a-service toolkit used for adversary-in-the-middle credential harvesting and account takeover. The service first emerged in August 2023, was later tracked by Microsoft under the name Storm-1747, became the most prolific platform Microsoft observed in 2025, and was tied to over 64,000 phishing incidents, tens of millions of phishing emails each month, and unauthorized access to nearly 100,000 organizations globally. The platform captured credentials, MFA codes, and session cookies, forwarded stolen data to Telegram for near-real-time monitoring, used short-lived FQDNs on Cloudflare, and targeted sectors including education, healthcare, finance, non-profit, and government; the operation also took down 330 domains used by the service.
Show sources
- Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks — thehackernews.com — 05.03.2026 08:51
- Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks — thehackernews.com — 05.03.2026 08:51