Tycoon2FA Is Beating Two-Factor Authentication—By Hijacking Your Logged-In Session in Seconds

Infos ITEnglishTycoon2FA Is Beating Two-Factor Authentication—By Hijacking Your Logged-In Session in Seconds

Two-factor authentication is supposed to be the safety net. Tycoon2FA is the scam that cuts the net—without “breaking” MFA at all.

Instead, this fast-growing phishing kit slips between you and the real login page for Microsoft 365 or Gmail, relays your password and MFA code in real time, then steals what actually matters: the authenticated session cookie. With that, attackers can log in as you—often without ever triggering MFA again.

A phishing kit that makes MFA feel optional

The setup is painfully familiar. An email lands in your inbox. You click. A Microsoft 365 or Google sign-in page looks perfect. You approve the push notification or type the one-time code and move on.

Behind the scenes, Tycoon2FA has already vacuumed up your credentials—and, crucially, your session token. That lets an attacker “replay” your already-approved session and walk right into your account as if they were sitting at your browser.

In many cases, even a password change won’t kick them out if your organization doesn’t revoke active sessions and invalidate tokens. Resetting the password and calling it done can leave the front door open.

“Phishing-as-a-service,” now with an admin dashboard

Tycoon2FA isn’t a one-off script tossed together by a lone hacker. It’s sold like a product: a phishing-as-a-service platform with a web-based control panel where operators can launch and manage campaigns.

That dashboard typically includes ready-made templates, hosting and domain settings, redirect logic, and victim tracking—turning phishing into something closer to running an ad campaign than writing code.

The accessibility is the point. You don’t need to be a reverse-proxy expert to run an adversary-in-the-middle (AiTM) attack when the platform does the heavy lifting. More skilled operators still benefit from the flexibility: multiple pages, multiple domains, multiple campaigns running at once.

Security researchers say Tycoon2FA started drawing serious attention in August 2023 and quickly scaled. Some incident trackers have placed it among the most widely deployed AiTM tools targeting everyday corporate identity accounts, with more than 64,000 reported incidents in a year in certain datasets.

This “shared platform” model also changes the economics. When defenses improve, the service updates—and every customer gets the upgrade. When a technique works, it spreads fast. That’s cybercrime industrialization in real time.

How Tycoon2FA gets around MFA without defeating it

Tycoon2FA doesn’t crack MFA. It uses it against you.

Its AiTM approach relies on a reverse proxy: a fake login page sits between the victim and the legitimate service. You enter your username and password. You approve the MFA prompt. The kit forwards everything instantly to Microsoft or Google, so the flow looks normal.

When the real service issues an authenticated session, Tycoon2FA captures the authentication tokens—especially the session cookie. With that cookie, an attacker doesn’t need your MFA again. They can reuse the session, bypassing the usual login friction and avoiding the noisy trail of failed sign-in attempts.

Researchers say these campaigns can relay most “classic” MFA methods, including SMS codes, authenticator app one-time passwords, and push notifications. MFA still blocks plenty of attacks—but AiTM phishing is a reminder that MFA alone isn’t a force field.

Why Microsoft 365 and Gmail are the prime targets

Tycoon2FA goes after the accounts that unlock everything else: Microsoft 365 (Outlook, OneDrive, SharePoint) and Google Workspace (including Gmail). If an attacker controls your email and files, they can often reset passwords elsewhere, intercept invoices, access HR conversations, and pivot into other business systems.

The pages are often copied pixel-for-pixel, and because the proxy talks to the real service live, victims may see the same MFA screens and even realistic error messages. For a busy employee moving fast, it’s easy to miss the trap.

Campaigns also lean on layered redirects—multiple hops before the fake login page—to complicate analysis and make the click path feel routine.

The persistence is what stings. If the attacker already has a valid session token, they may keep access even after a password reset unless IT explicitly revokes sessions and invalidates tokens.

CAPTCHAs, anti-analysis tricks, and rotating domains

Tycoon2FA isn’t just convincing—it’s built to stay online. Analysts describe common evasion features such as CAPTCHAs to filter bots, JavaScript anti-debugging to frustrate manual inspection, and infrastructure spread across multiple domains that rotate as defenders block them.

That domain rotation is key at scale: block one domain and another pops up. Take down one hosting provider and the campaign reappears elsewhere. For defenders, it becomes a constant chase that burns time and staffing.

Some anti-analysis features also aim to fool sandboxes and security researchers. If the page detects a suspicious environment, it may redirect or show different content—meaning an analyst might not see what the victim saw, at least not right away.

There’s a flip side: because the service is used by many operators, some make mistakes—reusing infrastructure or leaving fingerprints. But organizations have to be disciplined enough to capitalize on those errors.

What companies should do Monday morning

Start by retiring the idea that a password reset is the finish line. If session cookies are stolen, incident response needs to include revoking active sessions and invalidating tokens—every time. Make it a checklist item, not an optional step.

Next, push toward phishing-resistant authentication where possible. Since AiTM can relay SMS, one-time codes, and push approvals, those methods are more exposed in this model. In Microsoft 365 and Google environments, organizations can tighten defenses with conditional access policies, context-aware checks, and risk-based sign-in controls.

Training matters, but it has to match the threat. Employees need to see what AiTM looks like: a “real” login page, a normal MFA prompt, and a successful redirect—while the session is being stolen in the background. The simplest rule still holds: if you approve an MFA prompt you didn’t initiate, you may have just handed over the keys.

Finally, monitor what attackers can’t avoid: unusual sessions, new devices, impossible travel patterns, and suspicious access to sensitive resources right after authentication. Tycoon2FA is aimed squarely at business accounts, which means detection and response have to be built—and funded—on the enterprise side.

Key Takeaways

  • Tycoon2FA bypasses MFA by stealing session cookies via an AiTM proxy.
  • The kit is offered as phishing-as-a-service with an admin panel and ready-to-use templates.
  • Changing the password isn’t enough: you must revoke active sessions and tokens.

Frequently Asked Questions

Does Tycoon2FA “break” MFA?

No. It relays MFA in real time using an adversary-in-the-middle approach. You approve the code or push notification, then the kit captures authentication tokens—especially the session cookie—which the attacker can replay to log in without completing MFA again.

Which services are most targeted by Tycoon2FA?

The campaigns described mainly target widely used enterprise identity services, especially Microsoft 365 (Outlook, OneDrive, SharePoint) and Gmail/Google Workspace. The goal is to gain direct access to email and files, which often serve as a pivot to other applications.

Why might a simple password change not be enough?

Because the attacker may already have an active session thanks to the stolen cookie. If the organization doesn’t explicitly revoke sessions and reset tokens, access can remain possible even after a password reset.

What makes Tycoon2FA hard to detect?

The platform combines very convincing login pages with evasion mechanisms: CAPTCHAs, anti-debugging JavaScript, anti-analysis filtering, and multi-domain infrastructure with rotation. That makes rapid blocking and sandbox analysis more difficult.

Informations & Technologies chez Infos IT
Miguel Desforêt suit au quotidien l'actualité de l'informatique, de la cybersécurité et des nouvelles technologies. Il propose des analyses, des décryptages et des contenus spécialisés pour rendre les innovations plus accessibles. Pour enrichir ses recherches et optimiser sa production éditoriale, il s'appuie sur l'intelligence artificielle, avec une relecture et une validation systématiques avant publication.
Miguel desforet
spot_imgspot_img

Actualités

spot_img