Law enforcement disrupted Tycoon 2FA phishing-as-a-service platform
嗯,用户让我帮忙总结一下这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述就行。首先,我需要仔细阅读文章,抓住主要信息。 文章讲的是执法机构破坏了一个名为Tycoon 2FA的钓鱼服务平台。这个平台被用来发送数百万的钓鱼邮件到全球超过50万家组织。微软、欧洲刑警组织和行业伙伴一起行动,目标是破坏这个平台的基础设施。这个平台每月发送数千万的欺诈邮件,占了微软拦截的钓鱼攻击的大约62%。Resecurity获取了这个平台的访问权限,指出它被数千名网络罪犯用来伪装成真实用户,入侵邮箱和在线服务账户。他们还用了URL旋转和Cloudflare来逃避检测。 总结的时候,我需要涵盖这些关键点:执法机构破坏了Tycoon 2FA平台,该平台用于大规模钓鱼攻击,影响了全球大量组织和用户,并且使用了多种技术手段来逃避检测。同时,行动切断了主要的攻击管道,保护了用户免受进一步攻击。 现在把这些信息浓缩到100字以内。确保涵盖执法机构、平台名称、影响范围、技术手段以及行动的意义。 </think> 执法机构与微软等合作关停Tycoon 2FA钓鱼服务平台,该平台每月向全球50万家组织发送数千万钓鱼邮件,占微软拦截钓鱼攻击的62%。其利用URL旋转和Cloudflare等技术逃避检测,并伪装成真实用户入侵邮箱账户。此次行动切断了大规模账户接管及后续攻击的主要渠道。 2026-3-10 08:30:52 Author: securityaffairs.com(查看原文) 阅读量:6 收藏

Law enforcement disrupted Tycoon 2FA phishing-as-a-service platform

Authorities disrupted the Tycoon 2FA phishing-as-a-service platform used to send millions of phishing emails to over 500,000 orgs worldwide.

The joint effort, led by Microsoft, Europol, and industry partners, aimed to target the infrastructure of Tycoon 2FA phishing-as-a-service platform responsible for tens of millions of fraudulent emails reaching over 500,000 organizations each month worldwide.

By mid‑2025, the service accounted for approximately 62 percent of all phishing attempts Microsoft blocked, including more than 30 million emails in a single month. That placed Tycoon2FA among the largest phishing operations globally. Despite extensive defenses, the service is linked to an estimated 96,000 distinct phishing victims worldwide since 2023, including more than 55,000 Microsoft customers.

Resecurity acquired access to Tycoon 2FA, widely used by thousands of cybercriminals to impersonate real users and gain unauthorized access to email and online service accounts, including Microsoft 365, Outlook, and Gmail. As one of its evasion mechanisms, the PhaaS leveraged URL rotation by abusing open redirect vulnerabilities on third-party websites. Another mechanism that enables the protection of malicious instances generated by Tycoon 2FA is the misuse of Cloudflare (Workers).

“The author of Tycoon 2FA is actively updating the tool with regular kit updates.” reads the report published by Resecurity. “What makes Tycoon 2FA so special is that the kit effectively combines multiple methods to deliver phishing at scale—from PDF attachments to QR codes.”

Taking this infrastructure offline cuts off a major pipeline for account takeovers and helps protect people and organizations from follow‑on attacks such as data theft, ransomware, business email compromise, and financial fraud.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, PhaaS)




文章来源: https://securityaffairs.com/189205/cyber-crime/law-enforcement-disrupted-tycoon-2fa-phishing-as-a-service-platform.html
如有侵权请联系:admin#unsafe.sh