- Experts warn Tycoon2fa has been given new blur and evasion upgrades
- The platform is used to bypass MFA on Google and Microsoft accounts
- It is extremely popular among cyber criminals
Tycoon2FA, a notorious phishing-as-a-service (phaas) platform, has been much improved, and has become even more difficult to see and eliminate experts warned.
CyberSecurity scientists Trustwave said they have seen three new upgrades to the Phaas platform, best known for their ability to bypass Multi-Factor Protection (MFA) in Microsoft and Google Accounts.
It acts as an opponent-in-the-mid (AITM) attack, where he captures login credentials and session cookies to gain unauthorized access to user accounts, including those secured with MFA. It was also upgraded several times in the past, where its operators were mostly focused on displacement and evasion.
(Revolution
Now, Trustwave says Tycoon2fa uses invisible Unicode signs to hide binary data within human eyes javascript, avoid manual and static pattern-matching analysis.
Then it switched from Cloudflare Turnstil to a self-emitted CAPTCHA reproduced via HTML canvas with randomized elements, reportedly to bypass the fingerprints and marking of the domain’s reputation systems.
Finally, it now includes antidebugging javaScript code that detects browser automation tools and blocks some analytical tools.
These changes are not revolutionary or especially new in the phas ecosystem, reliable stresses. But when combined, they make detection and analysis much more difficult.
Tycoon 2FA was first spotted in the middle of 2023, but with the beginning of 2024 it has received a major upgrade, with the tool using approx. 1,100 domains and used in “thousands” of phishing attacks.
The platform is sold on underground forums with prices starting at $ 120 for 10 days of access, making it available to a wide range of cyber criminals.
Some researchers claim that the platform is very popular in the underground community. Apparently between August 2023 (when it was first launched) and March 2024, the Bitcoin cuttilled book for Operation Raked of more than $ 400,000 to Kryptos at that time.
Via Bleeping computer