Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
2026-03-05T14:52:21Z•6d209e4beb8b6a7564db70a201e40758eda4b2e41bb4ccf0506cae87ce10a672
AiTMC2Copilot-StudioEuropolMicrosoft DefenderMicrosoft-DCUNext.jsOAuth-redirection-abuseOpenClawRCERMM-backdoorSOC-fragmentationTycoon2FAagent-misconfigurationdeveloper-supply-chainphishing-as-a-servicesecurity-exposure-managementself-hosted-agentssigned-malwarestolen-EV-certificate
What happened
Microsoft Security Blog highlights multiple high‑impact threats and defensive guidance: Tycoon2FA — a leading AiTM phishing‑as‑a‑service — enabled campaigns reaching over 500,000 organizations monthly and was subject to disruption by Microsoft DCU, Europol, and partners. Separately, signed malware using a stolen EV certificate deployed legitimate RMM tools to establish persistent backdoors, while OAuth redirection abuse and malicious Next.js repositories have been weaponized to deliver phishing, malware, and covert RCE→C2 chains targeting developers and enterprises. The posts also call out the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 6d209e4beb8b6a7564db70a201e40758eda4b2e41bb4ccf0506cae87ce10a672
- Enrichment time
- 2026-03-05T14:52:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.