Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale

2026-03-05T08:52:25Z0b9bc15b6858990607a1b23df86bf8ee8f2c519f3c6c503ccd43ef21a90fe164
AiTMC2Copilot StudioEV certificateEuropolMicrosoft DefenderMicrosoft Digital Crimes UnitNext.jsOAuth redirection abuseOpenClawPhaaSRMMSOC consolidationTycoon2FAagent misconfigurationbackdoorbuild‑time RCEdeveloper supply chainphishingself‑hosted agentssigned malwarethreat modeling

What happened

This feed summarizes multiple Microsoft Security Blog posts describing high‑impact threats and defensive guidance. Key items: disruption of Tycoon2FA, a large AiTM/PhaaS phishing kit reaching hundreds of thousands of organizations (Microsoft DCU + Europol action); signed malware using a stolen EV certificate to deploy legitimate RMM tools and establish persistent backdoors; OAuth redirection abuse used to convert trusted auth flows into phishing/malware delivery; a developer‑targeting campaign that used malicious Next.js repositories to trigger build‑time RCE leading to covert C2; and risks of

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
0b9bc15b6858990607a1b23df86bf8ee8f2c519f3c6c503ccd43ef21a90fe164
Enrichment time
2026-03-05T08:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale · Baitaphish