Also known as: the Saad Tycoon Group, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, reverse proxy server
Saad Tycoon is the operator and alleged developer of the Tycoon 2FA PhaaS, a phishing service that targets users for financial gain. The actor utilizes Bitcoin transactions to generate significant profits from the fraudulent service. The phishing infrastructure includes domain registration, server hosting, and possibly Cloudflare protection.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Saad Tycoon operates the Tycoon 2FA PhaaS, a phishing service targeting users for financial gain through Two-Factor Authentication (2FA) exploitation. The actor monetizes fraudulent activities using Bitcoin transactions and maintains a robust infrastructure involving domain registration and server hosting. Confidence in this assessment is moderate based on available open-source intelligence, though additional details regarding specific campaigns or TTPs remain unclear.
Goals & Targeting
Saad Tycoon's primary goal appears to be Financial Gain through the exploitation of Two-Factor Authentication systems. The actor targets users and organizations that rely on 2FA for securing sensitive accounts, particularly those in sectors where financial transactions are frequent or high-value. This targeting likely reflects an understanding of the perceived security provided by 2FA and a strategy to bypass it through phishing techniques. The actor's focus on financial gain aligns with trends in cybercriminal activity aiming to compromise financial institutions or individuals with access to valuable assets.
Enhanced Description
Saad Tycoon is a threat actor who operates the Tycoon 2FA Phishing as-a-Service (PhaaS) platform. This service facilitates phishing attacks targeting users' two-factor authentication (2FA) mechanisms, enabling the theft of sensitive credentials and financial information. The actor leverages Bitcoin transactions to monetize fraudulent activities, indicating a focus on financial gain. The Tycoon PhaaS infrastructure appears to include domain registration, server hosting, and possibly Cloudflare protection, suggesting an attempt to anonymize and protect the operation from law enforcement and cybersecurity responses. While no specific campaigns have been publicly linked to Saad Tycoon yet, the actor's operations likely involve targeting individuals or organizations with access to valuable financial information. The use of 2FA phishing indicates a sophisticated approach, as 2FA is commonly seen as an additional layer of security.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
Saad Tycoon's campaigns likely involve spear-phishing emails, social engineering, and the distribution of malicious links or payloads to compromise users' 2FA systems. The actor may target specific regions with high financial transaction volumes or industries with valuable data. Notable operations have not been publicly reported due to limited open-source intelligence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in this assessment is moderate. While the existence of the Tycoon PhaaS platform and associated infrastructure is clear, specific details about campaigns, TTPs, or tools used by Saad Tycoon remain limited to open-source intelligence. There are no publicly available MITRE ATT&CK mappings for this actor, which creates gaps in understanding their exact capabilities and tactics.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics