Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale

2026-03-04T20:52:25Ze8249ef92748abb598dc36fe8505a2ea262d8a7de5b3a41ab9721daf1b8e024b
AI-threat-modelingAiTMC2Copilot-StudioEuropolMicrosoft-DCUNext.jsOAuth-abuseOpenClawRCERMMSOCTycoon2FAagent-misconfigurationsmalware-deliverypersistencephishingphishing-as-a-servicesecurity-exposure-managementsecurity-operationssigned-malwarestolen-EV-certificatesupply-chain

What happened

Collection of Microsoft Security Blog posts describing multiple high-impact threats and operational guidance. Highlights include: disruption of Tycoon2FA, a large AiTM phishing‑as‑a‑service platform that targeted >500,000 organizations monthly; signed malware using a stolen EV certificate to deploy legitimate RMM tools for persistent access; OAuth redirection abuse to weaponize trusted auth flows for phishing and malware delivery; developer‑targeting via malicious Next.js repositories that trigger RCE→C2 through normal build workflows; and guidance on AI threat modeling, agent/OpenClaw runtime

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
e8249ef92748abb598dc36fe8505a2ea262d8a7de5b3a41ab9721daf1b8e024b
Enrichment time
2026-03-04T20:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.