Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Saad Tycoon

Also known as: the Saad Tycoon Group, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, reverse proxy server

Description

Saad Tycoon is the operator and alleged developer of the Tycoon 2FA PhaaS, a phishing service that targets users for financial gain. The actor utilizes Bitcoin transactions to generate significant profits from the fraudulent service. The phishing infrastructure includes domain registration, server hosting, and possibly Cloudflare protection.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Energy
Telecommunications
Aerospace
Media
Education
Information technology
Maritime
Healthcare
Manufacturing
Think tank
Pharmaceutical
Chemical
Mining
Construction
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
DE
JP
KR
IR
RU
SA
FR
CA
TW
IL
TR
AU
KZ
PK
VN
UA
PL
ES
AE
SG
NL
BR
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

· 1 week ago

Executive Summary

Saad Tycoon operates the Tycoon 2FA PhaaS, a phishing service targeting users for financial gain through Two-Factor Authentication (2FA) exploitation. The actor monetizes fraudulent activities using Bitcoin transactions and maintains a robust infrastructure involving domain registration and server hosting. Confidence in this assessment is moderate based on available open-source intelligence, though additional details regarding specific campaigns or TTPs remain unclear.

Goals & Targeting

Saad Tycoon's primary goal appears to be Financial Gain through the exploitation of Two-Factor Authentication systems. The actor targets users and organizations that rely on 2FA for securing sensitive accounts, particularly those in sectors where financial transactions are frequent or high-value. This targeting likely reflects an understanding of the perceived security provided by 2FA and a strategy to bypass it through phishing techniques. The actor's focus on financial gain aligns with trends in cybercriminal activity aiming to compromise financial institutions or individuals with access to valuable assets.

Enhanced Description

Saad Tycoon is a threat actor who operates the Tycoon 2FA Phishing as-a-Service (PhaaS) platform. This service facilitates phishing attacks targeting users' two-factor authentication (2FA) mechanisms, enabling the theft of sensitive credentials and financial information. The actor leverages Bitcoin transactions to monetize fraudulent activities, indicating a focus on financial gain. The Tycoon PhaaS infrastructure appears to include domain registration, server hosting, and possibly Cloudflare protection, suggesting an attempt to anonymize and protect the operation from law enforcement and cybersecurity responses. While no specific campaigns have been publicly linked to Saad Tycoon yet, the actor's operations likely involve targeting individuals or organizations with access to valuable financial information. The use of 2FA phishing indicates a sophisticated approach, as 2FA is commonly seen as an additional layer of security.

Key Capabilities

  • Development and operation of Phishing as-a-Service (PhaaS) platforms targeting 2FA
  • Use of Bitcoin for monetization of stolen credentials
  • Infrastructure setup including domain registration, server hosting, and potential use of Cloudflare protection

MITRE ATT&CK Tactics

Initial Access
Credential Access

Software / Tooling

Phishing-as-a-Service (PhaaS) platforms
Bitcoin wallets for transactions

Campaigns & Victims

Saad Tycoon's campaigns likely involve spear-phishing emails, social engineering, and the distribution of malicious links or payloads to compromise users' 2FA systems. The actor may target specific regions with high financial transaction volumes or industries with valuable data. Notable operations have not been publicly reported due to limited open-source intelligence.

IOC Patterns

  • Phishing campaigns targeting 2FA systems
  • Use of Bitcoin wallets for transactions
  • Malicious domains registered for phishing infrastructure

Recommended Actions

  • Enhance employee training on phishing and social engineering tactics
  • Implement robust detection mechanisms for PhaaS-related activities
  • Monitor for unusual login patterns and account compromises

Suggested Tags

Cybercrime
Phishing
Two-Factor Authentication (2FA)
Financial Fraud

Confidence Assessment

Confidence in this assessment is moderate. While the existence of the Tycoon PhaaS platform and associated infrastructure is clear, specific details about campaigns, TTPs, or tools used by Saad Tycoon remain limited to open-source intelligence. There are no publicly available MITRE ATT&CK mappings for this actor, which creates gaps in understanding their exact capabilities and tactics.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 5 IPv4 Address 15

References

  1. misp-galaxy.org — Cited by web research for: cpyy
  2. www.sekoia.com — Cited by web research for: reverse proxy server
  3. any.run — Cited by web research for: Unknown
  4. www.proofpoint.com — Cited by web research for: Nexus

Intel Summary

0

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Cybercrime
Two-Factor Authentication (2FA)
Financial Fraud

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.