Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale

2026-03-05T14:52:21Z6d209e4beb8b6a7564db70a201e40758eda4b2e41bb4ccf0506cae87ce10a672
AiTMC2Copilot-StudioEuropolMicrosoft DefenderMicrosoft-DCUNext.jsOAuth-redirection-abuseOpenClawRCERMM-backdoorSOC-fragmentationTycoon2FAagent-misconfigurationdeveloper-supply-chainphishing-as-a-servicesecurity-exposure-managementself-hosted-agentssigned-malwarestolen-EV-certificate

What happened

Microsoft Security Blog highlights multiple high‑impact threats and defensive guidance: Tycoon2FA — a leading AiTM phishing‑as‑a‑service — enabled campaigns reaching over 500,000 organizations monthly and was subject to disruption by Microsoft DCU, Europol, and partners. Separately, signed malware using a stolen EV certificate deployed legitimate RMM tools to establish persistent backdoors, while OAuth redirection abuse and malicious Next.js repositories have been weaponized to deliver phishing, malware, and covert RCE→C2 chains targeting developers and enterprises. The posts also call out the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
6d209e4beb8b6a7564db70a201e40758eda4b2e41bb4ccf0506cae87ce10a672
Enrichment time
2026-03-05T14:52:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.