Tycoon 2FA Phishing Kit Grows More Sophisticated

KnowBe4 Team | Nov 13, 2025

MFACybereason warns that the Tycoon 2FA phishing kit continues to receive upgrades, allowing unskilled cybercriminals to launch sophisticated social engineering attacks. The platform is known for its ability to bypass multi-factor authentication measures.

“The Tycoon 2FA phishing kit is a sophisticated Phishing-as-a-Service (PhaaS) platform that emerged in August 2023, designed to bypass two-factor authentication (2FA) and multi-factor authentication (MFA) protections, primarily targeting Microsoft 365 and Gmail accounts,” Cybereason says.

“Utilizing an Adversary-in-the-Middle (AiTM) approach, it employs a reverse proxy server to host deceptive phishing pages that mimic legitimate login interfaces, capturing user credentials and session cookies in real-time. According to the Any.run malware trends tracker, Tycoon 2FA leads with over 64,000 reported incidents this year.”

Notably, the phishing kit can modify its approach based on error messages received during login attempts.

“A particularly advanced feature of the Tycoon 2FA campaign is its ability to understand an organization’s specific security policies,” the researchers write. “By analyzing error messages from the login process, the phishing kit can tailor its attacks to create highly targeted campaigns, increasing its chances of successfully stealing credentials.”

Employee training is an essential layer of defense against phishing attacks. Cybereason offers the following advice to help organizations thwart these attacks:

  • “Train users to recognize suspicious activities and phishing attempts to minimize reinfection risks.
  • Teach identification of modified or misspelled URLs and grammatical errors in communications.
  • Educate users on the risks of malicious files (e.g., PDFs, PPTs, Word documents, and SVG files) that may redirect to phishing websites.”

AI-powered security awareness training can give your employees a healthy sense of suspicion so they can avoid falling for these attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

Cybereason has the story.


AI-Powered Security Awareness Training Demo

KnowBe4 AIDA — Artificial Intelligence Defense Agents: a suite of agents that up-levels your approach to human risk management.

AIDA Logo

With AIDA you can:

  • Ensure your SAT is consistent with your organization’s broader security initiatives by aligning with the NIST Phish Scale Framework
  • Dramatically free up your security team's time by reducing how long it takes your admins to create remedial training
  • Improve relationships between your security team and other departments by ensuring users are aligned with security objectives
  • Ensure flexibility in your security budget to invest in other key initiatives by actively managing human risk
  • Maximize the value of your existing security tech stack with AIDA’s seamless integrations

Request A Demo

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/products/aida-demo



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.