Europol-coordinated action disrupts Tycoon2FA phishing platform
好的,我现在需要帮用户总结一篇文章,控制在100字以内。首先,我得仔细阅读文章内容,抓住关键点。 文章讲的是一个国际执法行动,由欧洲刑警组织协调,打击了一个名为Tycoon2FA的钓鱼服务。这个平台每月发送数千万钓鱼信息,影响了近十万组织。执法行动中没收了330个域名,涉及微软和其他公司的合作。此外,Tycoon2FA允许攻击者绕过双因素认证,危害很大。 接下来,我需要把这些信息浓缩成一句话。要包含执法机构、行动结果、影响范围和平台的危害。确保不超过100字,并且直接描述内容,不使用总结性的开头。 可能的结构是:国际执法行动打击钓鱼平台Tycoon2FA,没收330个域名,影响近十万组织,绕过双因素认证。 检查字数是否合适,并确保信息准确无误。 </think> 国际执法机构协调打击钓鱼服务平台Tycoon2FA,没收其330个域名并关停相关基础设施,该平台每月发送数千万钓鱼信息并被用于绕过多因素认证保护。 2026-3-4 17:15:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:3 收藏

Phishing

An international law enforcement operation coordinated by Europol has disrupted Tycoon2FA, a major phishing-as-a-service (PhaaS) platform linked to tens of millions of phishing messages each month.

In total, 330 domains part of the criminal service's backbone infrastructure (including control panels and phishing pages) were seized and taken offline during this joint action.

"The technical disruption was led by Microsoft with the support of a coalition of private partners, while seizure of infrastructure and other operational measures were carried out by law enforcement in Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom – all of this coordinated by Europol," Europol said on Wednesday.

"The investigation began after intelligence was shared by Trend Micro. Europol disseminated this information through its EC3 Advisory Groups and operational networks, enabling a coordinated operational strategy to be developed."

The action was also supported by Cloudflare, Coinbase, Intel471, Proofpoint, Shadowserver Foundation, SpyCloud, eSentire, Crowell, Resecurity, and Health-ISAC.

Tycoon2FA (also known as Tycoon 2FA) has been active since at least August 2023 and was used by cybercriminals to bypass multi-factor authentication (MFA) protections and compromise accounts belonging to nearly 100,000 organizations worldwide, including government institutions, schools, and healthcare organizations.

According to Microsoft, Tycoon2FA was generating tens of millions of phishing emails each month by mid-2025, reaching more than 500,000 organizations and accounting for 60% of all blocked phishing attempts.

Tycoon2FA volume of phishing messages
Tycoon2FA volume of phishing messages (Microsoft)

​It operated as an adversary-in-the-middle platform, using a reverse proxy server to intercept victims' login credentials and session cookies in real time, in attacks targeting Microsoft and Google customers.

However, it allowed attackers to hijack authenticated sessions and circumvent MFA protections, even though the login process appeared to succeed normally from the victims' perspective.

"Tycoon2FA's platform enabled threat actors to impersonate trusted brands by mimicking sign-in pages for services like Microsoft 365, OneDrive, Outlook, SharePoint, and Gmail. It also allowed threat actors using its service to establish persistence and to access sensitive information even after passwords are reset, unless active sessions and tokens were explicitly revoked," Microsoft said today.

"This worked by intercepting session cookies generated during the authentication process, simultaneously capturing user credentials. The MFA codes were subsequently relayed through Tycoon2FA's proxy servers to the authenticating service."

Sold through Telegram for $120 for 10 days of access, Tycoon2FA lowered the barrier for low-skilled criminals to launch sophisticated, MFA-bypassing attacks at scale.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/europol-coordinated-action-disrupts-tycoon2fa-phishing-platform/
如有侵权请联系:admin#unsafe.sh