"Phishing Kit Targets Microsoft 365 and Gmail Accounts with New MFA-Bypassing Technique"

1 min read
Source: BleepingComputer
"Phishing Kit Targets Microsoft 365 and Gmail Accounts with New MFA-Bypassing Technique"
Photo: BleepingComputer
TL;DR Summary

Cybercriminals are using a new phishing-as-a-service platform called 'Tycoon 2FA' to target Microsoft 365 and Gmail accounts, bypassing two-factor authentication. The platform has been active since at least August 2023 and has recently released a stealthier version. The attacks involve a multi-step process to steal session cookies and bypass MFA mechanisms. The latest version of the kit has introduced significant modifications to improve phishing and evasion capabilities, and evidence suggests a broad user base of cybercriminals utilizing Tycoon 2FA for phishing operations.

Share this article

Reading Insights

Total Reads

0

Unique Readers

15

Time Saved

3 min

vs 4 min read

Condensed

87%

61782 words

Want the full story? Read the original article

Read on BleepingComputer