Also known as: tracked as
Storm‑1747 emerged in mid‑2023 as the developers behind Tycoon 2FA, a sophisticated phishing‑as‑a‑service platform. The kit offers a web‑based administration panel that lets operators configure realistic fake login pages for Microsoft 365 and Google Workspace, choose custom CAPTCHA challenges, set MFA interception rules, and track victim interactions in real time. Clients can manipulate every facet of the phishing flow—template selection, branding, redirection logic, and exfiltration settings—making it trivial even for less technical actors to launch large‑scale campaigns. Tycoon 2FA distinguished itself by continuous evolution: custom CAPTCHA rotations, dynamic code generation, dead code insertion, and automated fallback to decoy pages when a target’s geolocation does not match the approved region. The platform’s AiTM capability allows attackers to capture authenticated session cookies and MFA tokens, effectively bypassing two‑factor authentication without revealing the phishing link. At its peak Tycoon 2FA accounted for roughly 62 % of Microsoft’s blocked phishing attempts, impacting over half a million organizations each month. In response, Microsoft’s Digital Crimes Unit collaborated with Europol to disrupt Tycoon 2FA infrastructure. Despite this effort, the kit’s architecture and widespread distribution model continue to pose significant risk across a broad spectrum of industries.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑1747 is a cybercriminal intrusion set centered on the Tycoon 2FA phishing-as-a-service kit, which became dominant in 2023‐24 and has distributed millions of deceptive emails. The kit delivers advanced adversary-in-the-middle (AiTM) capabilities that bypass MFA and capture session tokens, allowing the actor to compromise high‑value accounts across finance, government, healthcare, education and other sectors worldwide.
Goals & Targeting
Storm‑1747 primarily seeks financial gain through credential theft, exploiting MFA‑bypassing capabilities to accumulate large volumes of valid login sessions and tokens. By targeting high‑profile sectors—finance, defense, healthcare, education, media, government, nonprofits, think‑tanks, and construction—the actor maximises potential for direct monetary fraud, data exfiltration, or resale of compromised accounts on underground markets. The geographical reach (US, Israel, Russia, North Korea, India, Germany, France, Spain, Canada, United Kingdom) reflects both the ubiquitous nature of cloud services and the low technical barrier presented by Tycoon 2FA. Typical victims are mid‑ to large‑sized enterprises with many employees, especially those relying on Microsoft 365 or Google Workspace for daily operations. Overall, Storm‑1747 operates at scale, leveraging a PhaaS model that enables mass phishing campaigns while keeping operational risk low for individual clients.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑1747 campaigns are driven by a subscription‑based PhaaS model, enabling attackers to rapidly launch thousands of spear‑phishing messages per month across diverse sectors. The actor’s operational tempo is high: daily email blasts target hundreds of thousands of addresses with realistic impersonations of trusted services. Victim profiles tend toward large enterprises and organizations with cloud endpoints that require MFA. The kit’s AI‑enabled landing pages, coupled with dynamic CAPTCHAs, reduce automated detection, while exfiltration over HTTPS to the central panel mitigates low‑visibility in corporate networks. Notable operations include a series of campaigns observed in late 2023 and early 2024 that compromised MFA tokens for both Microsoft 365 and Google Workspace users. The actor’s pattern also shows repeated use of Telegram for immediate notification of credential harvests, facilitating rapid secondary monetization.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly available information from Microsoft Threat Intelligence, the Malpedia actor page, and multiple reports describing Tycoon 2FA’s operation. While the technical capabilities of the kit are well documented, attribution details such as internal structure or state sponsorship remain unclear. Confidence in the kit’s usage patterns and TTPs is high; however, gaps persist regarding the actor's origin, long‑term operational longevity, and full extent of global reach.
No campaigns linked yet.
No observed data linked yet.
47
Techniques
48
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics