New Tycoon 2FA Phishing Kit Attacking Microsoft 365 & Gmail Users

Hackers use 2FA (Two-Factor Authentication) phishing kits to overcome the additional security layer provided by 2FA.  These kits typically mimic legitimate login pages and prompt users to enter their credentials along with the one-time passcodes generated by their authenticator apps or sent via SMS. Through proactive threat hunting, Sekoia analysts uncovered a new and widespread Adversary-in-The-Middle (AiTM) phishing kit called Tycoon 2FA in October 2023.  This Phishing-as-a-Service (PhaaS) platform has been actively used by multiple threat actors since at least August 2023 to conduct effective phishing attacks.  Continuous monitoring revealed Tycoon 2FA as one of the most prevalent AiTM kits, with over 1,100 associated domains identified between late October 2023 and late February 2024.

Source: GBHackers

 


Date:

Categorie(s):

Tag(s):