Target Industry
Indiscriminate, opportunistic targeting.
Overview
The group Tycoon2FA has released an update for its popular phishing tool, which it sells. Tycoon2FA operates as a Phishing as a Service (PhaaS) and its tool bypasses multi-factor authentication (MFA) by stealing information such as credentials and cookies. The group does this through emails that link to an authentic redirect site which lands people on their phishing site. This is often disguised as a Microsoft 365 or Gmail login page. This tool can be purchased on Telegram for as little as $120, allowing accessibility to most criminals.
Exploitation
The update increases the tool’s capacity for evasion and stealth by three major changes:
- Invisible Unicode character: Using an invisible Unicode character in the JavaScript makes it difficult to detect through static analysis
- Self-hosted CAPTCHA : Switched from using Cloudflare Turnstile to a self-hosted CAPTCHA rendered through HTML canvas with randomised elements. This allows the group to have more control over the CAPTCHA as well as avoiding being reported and fingerprinted by security teams for hosting a phishing site. If during the CAPTCHA the server thinks that the user attempting login is a bot, it will forward it to a legitimate site. This decreases the chance of automated security sweeps from viewing the phishing site
- Anti debugging via JavaScript: The tool uses JavaScript to increase difficulty and slow down security teams’ investigations. It stops automated tools such as Burp Suite and PhantomJS from running scans, blocks dev tools shortcuts, and prevent right clicking, which is used to access the inspect element and redirects to another site if analysis is suspected.
Impact
The increase in evasion and obfuscation of the tool’s phishing sites will result in less accurate threat intelligence. This is highly likely to cause less effective detectability for managed security services providers (MSSP) when a user visits a phishing site. It’s highly likely this will result in more users falling for phishing emails and websites without anyone knowing, resulting in the theft of credentials. This will result in the business having unknown exposed accounts which is likely to result in data theft, slow or stop operations, and lose trust with customers.
Containment, Mitigations & Remediations
Mitigating the risks posed by advanced phishing kits like Tycoon2FA requires a multi-layered approach. Here are some effective strategies:
- Enhance email security: use advanced email filtering and implement more robust MFA solutions
- Regular software updates: ensure all systems and software are up to date with the latest security patches, closing any vulnerabilities
- Employee training and awareness: set up phishing awareness training and use phishing simulations to help employees recognise and avoid phishing attempts
- Strong password policies: use strong, unique passwords and regular password changes, along with password managers
- Yara detection rule can be found at Breakdown of Tycoon Phishing-as-a-Service System which detects repeated use of Unicode characters. This will detect when a user visits the site.
Threat Landscape
Tycoon2FA PhaaS is a threat to most organisations as it is primarily used to steal Microsoft credentials which the majority of organisation require to operate. Due to its intensive evasion technique and low price, Tycoon2FA poses a significant and ongoing cyber threat.
Threat Group
Tycoon2FA PhaaS has no disclosed country of origin or motivation except financial. The group was first seen in August 2023.
Further Information













