Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
2026-03-05T08:52:25Z•0b9bc15b6858990607a1b23df86bf8ee8f2c519f3c6c503ccd43ef21a90fe164
AiTMC2Copilot StudioEV certificateEuropolMicrosoft DefenderMicrosoft Digital Crimes UnitNext.jsOAuth redirection abuseOpenClawPhaaSRMMSOC consolidationTycoon2FAagent misconfigurationbackdoorbuild‑time RCEdeveloper supply chainphishingself‑hosted agentssigned malwarethreat modeling
What happened
This feed summarizes multiple Microsoft Security Blog posts describing high‑impact threats and defensive guidance. Key items: disruption of Tycoon2FA, a large AiTM/PhaaS phishing kit reaching hundreds of thousands of organizations (Microsoft DCU + Europol action); signed malware using a stolen EV certificate to deploy legitimate RMM tools and establish persistent backdoors; OAuth redirection abuse used to convert trusted auth flows into phishing/malware delivery; a developer‑targeting campaign that used malicious Next.js repositories to trigger build‑time RCE leading to covert C2; and risks of
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 0b9bc15b6858990607a1b23df86bf8ee8f2c519f3c6c503ccd43ef21a90fe164
- Enrichment time
- 2026-03-05T08:52:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.