Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
2026-03-04T20:52:25Z•e8249ef92748abb598dc36fe8505a2ea262d8a7de5b3a41ab9721daf1b8e024b
AI-threat-modelingAiTMC2Copilot-StudioEuropolMicrosoft-DCUNext.jsOAuth-abuseOpenClawRCERMMSOCTycoon2FAagent-misconfigurationsmalware-deliverypersistencephishingphishing-as-a-servicesecurity-exposure-managementsecurity-operationssigned-malwarestolen-EV-certificatesupply-chain
What happened
Collection of Microsoft Security Blog posts describing multiple high-impact threats and operational guidance. Highlights include: disruption of Tycoon2FA, a large AiTM phishing‑as‑a‑service platform that targeted >500,000 organizations monthly; signed malware using a stolen EV certificate to deploy legitimate RMM tools for persistent access; OAuth redirection abuse to weaponize trusted auth flows for phishing and malware delivery; developer‑targeting via malicious Next.js repositories that trigger RCE→C2 through normal build workflows; and guidance on AI threat modeling, agent/OpenClaw runtime
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- e8249ef92748abb598dc36fe8505a2ea262d8a7de5b3a41ab9721daf1b8e024b
- Enrichment time
- 2026-03-04T20:52:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.