osec.one case analysis cover: adversary-in-the-middle phishing and session theft

Multi-factor authentication stopped most password-only phishing. Attackers adapted by no longer trying to beat MFA and instead letting the victim complete it for them. Tycoon2FA, run by a group Microsoft tracks as Storm-1747, turned that idea into a product. From August 2023 it was sold on Telegram as phishing-as-a-service. In March 2026 Microsoft's Digital Crimes Unit, working with Europol and industry partners, took down its infrastructure.

At its peak, Microsoft says, campaigns built on Tycoon2FA sent tens of millions of phishing messages reaching over 500,000 organisations each month, across education, healthcare, finance, non-profits and government.

Attack chain: lure email, CAPTCHA and bot filter, reverse proxy shows real login page, victim completes MFA, kit captures session cookie, attacker replays session
Adversary-in-the-middle: the victim logs in to the real service, through the attacker.

Step 1: lures that survive email filters

Messages impersonated Microsoft 365, Outlook, Gmail, e-signature and voicemail notices. Links were hidden in PDFs, SVG images, HTML attachments and QR codes, formats that many filters inspect less closely than a plain URL. Links often went through redirect chains on legitimate services before reaching the kit.

Step 2: keep the researchers out

Before showing anything, the kit screened the visitor. It used anti-bot checks, browser fingerprinting, self-hosted CAPTCHAs, heavily obfuscated JavaScript and decoy pages for anything that looked like a sandbox or scanner. The infrastructure rotated through short-lived subdomains (24 to 72 hours) across many TLDs, mostly behind Cloudflare, so blocklists were always behind.

Step 3: the reverse proxy

This is the core of every AiTM kit (Evilginx is the best-known open-source example). The phishing server doesn't host a fake copy of the login page. It proxies the real one:

1. The victim's browser talks to the phishing domain.
2. The phishing server forwards each request to the real Microsoft or Google login and passes the responses back, rewriting links as it goes.
3. The victim sees their real tenant branding, enters their password, and gets a real MFA prompt: an SMS code, an authenticator code or a push approval.
4. They complete it. The identity provider issues a session cookie, and it passes through the proxy, which keeps a copy.

The attacker imports that cookie into their own browser and is signed in. No password prompt and no MFA, because as far as the service is concerned the session is already authenticated.

One-time codes, authenticator apps and push approvals prove that the user is present. They don't prove which website the user is talking to. That gap is what AiTM exploits.

Step 4: what happens after

With a live session the attacker typically reads mail, adds an inbox rule to hide replies, registers their own MFA method for persistence, and launches business email compromise or internal phishing from the trusted account.

What actually stops it

Phishing-resistant authentication

Passkeys and FIDO2 security keys bind the login to the website's origin. The browser won't use a passkey for login.microsoftonline.com on a page served from a look-alike domain, so the proxy has nothing to relay. Windows Hello for Business and certificate-based auth give the same protection. This is Microsoft's first recommendation, and it is the only control that removes the technique rather than raising its cost.

Make stolen cookies less useful

• Conditional access that requires a compliant or managed device: the attacker's browser isn't one.
• Token protection / session binding where your identity provider supports it.
• Shorter session lifetimes for sensitive apps, and re-authentication for high-risk actions.

Detection and response

• Alert on a session used from a new IP or ASN minutes after a successful sign-in from a different one.
• Alert on new MFA methods and new inbox rules, especially rules that move or delete mail.
• On a confirmed hit, revoke sessions and refresh tokens. A password reset alone doesn't end a stolen session.
• Enable link and attachment detonation (Safe Links / Safe Attachments or equivalents) and zero-hour purge of delivered messages.

After the takedown

Taking down one PhaaS brand disrupts its customers for a while, but the technique is open source and well understood. Expect successors. Moving your important logins to passkeys and one-time codes tied to your own domain does more than any blocklist.

osec.one adds one-time-code and Apple/Google sign-in to your app or website in minutes. Free to start.

Get started with osec.one

Sources: Microsoft Security blog, Inside Tycoon2FA (4 Mar 2026); Cybereason: Tycoon phishing kit analysis; Infosecurity Magazine: new Tycoon 2FA kit; FIDO Alliance: passkeys.