Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-1747

Also known as: tracked as

Description

Storm‑1747 emerged in mid‑2023 as the developers behind Tycoon 2FA, a sophisticated phishing‑as‑a‑service platform. The kit offers a web‑based administration panel that lets operators configure realistic fake login pages for Microsoft 365 and Google Workspace, choose custom CAPTCHA challenges, set MFA interception rules, and track victim interactions in real time. Clients can manipulate every facet of the phishing flow—template selection, branding, redirection logic, and exfiltration settings—making it trivial even for less technical actors to launch large‑scale campaigns. Tycoon 2FA distinguished itself by continuous evolution: custom CAPTCHA rotations, dynamic code generation, dead code insertion, and automated fallback to decoy pages when a target’s geolocation does not match the approved region. The platform’s AiTM capability allows attackers to capture authenticated session cookies and MFA tokens, effectively bypassing two‑factor authentication without revealing the phishing link. At its peak Tycoon 2FA accounted for roughly 62 % of Microsoft’s blocked phishing attempts, impacting over half a million organizations each month. In response, Microsoft’s Digital Crimes Unit collaborated with Europol to disrupt Tycoon 2FA infrastructure. Despite this effort, the kit’s architecture and widespread distribution model continue to pose significant risk across a broad spectrum of industries.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Non profit
Healthcare
Education
Think tank
Media
Construction

Targeted Countries / Regions

US
IL
RU
KP
IN
DE
FR
ES
CA
GB

AI Analysis

Grounded in web research
· 1 hour ago

Executive Summary

Storm‑1747 is a cybercriminal intrusion set centered on the Tycoon 2FA phishing-as-a-service kit, which became dominant in 2023‐24 and has distributed millions of deceptive emails. The kit delivers advanced adversary-in-the-middle (AiTM) capabilities that bypass MFA and capture session tokens, allowing the actor to compromise high‑value accounts across finance, government, healthcare, education and other sectors worldwide.

Goals & Targeting

Storm‑1747 primarily seeks financial gain through credential theft, exploiting MFA‑bypassing capabilities to accumulate large volumes of valid login sessions and tokens. By targeting high‑profile sectors—finance, defense, healthcare, education, media, government, nonprofits, think‑tanks, and construction—the actor maximises potential for direct monetary fraud, data exfiltration, or resale of compromised accounts on underground markets. The geographical reach (US, Israel, Russia, North Korea, India, Germany, France, Spain, Canada, United Kingdom) reflects both the ubiquitous nature of cloud services and the low technical barrier presented by Tycoon 2FA. Typical victims are mid‑ to large‑sized enterprises with many employees, especially those relying on Microsoft 365 or Google Workspace for daily operations. Overall, Storm‑1747 operates at scale, leveraging a PhaaS model that enables mass phishing campaigns while keeping operational risk low for individual clients.

Enhanced Description

Key Capabilities

  • Phishing-as-a-service platform
  • Adversary-in-the-middle MFA bypass
  • Custom CAPTCHA generation and rotation
  • Dynamic code injection and dead code insertion
  • Victim interaction tracking via web dashboard
  • Real‑time session cookie and token exfiltration
  • Use of Telegram for command and control
  • Geolocation‑based content delivery
  • Decoy page fallback to avoid detection

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Defense Evasion
Privilege Escalation
Collection
Command and Control

ATT&CK Techniques

T1566.002
T1598.003
T1059.001
T1134.004
T1550.001
T1571
T1584
T1542
T1055
T1110
T1003
T1110.001

Software / Tooling

Tycoon 2FA Kit
Microsoft 365 Phishing Module
Google Workspace Phishing Module
Custom CAPTCHA Engine
Telegram Bot C&C
Session Cookie Exfiltration Scripts

Campaigns & Victims

Storm‑1747 campaigns are driven by a subscription‑based PhaaS model, enabling attackers to rapidly launch thousands of spear‑phishing messages per month across diverse sectors. The actor’s operational tempo is high: daily email blasts target hundreds of thousands of addresses with realistic impersonations of trusted services. Victim profiles tend toward large enterprises and organizations with cloud endpoints that require MFA. The kit’s AI‑enabled landing pages, coupled with dynamic CAPTCHAs, reduce automated detection, while exfiltration over HTTPS to the central panel mitigates low‑visibility in corporate networks. Notable operations include a series of campaigns observed in late 2023 and early 2024 that compromised MFA tokens for both Microsoft 365 and Google Workspace users. The actor’s pattern also shows repeated use of Telegram for immediate notification of credential harvests, facilitating rapid secondary monetization.

IOC Patterns

  • Phishing emails with domain spoofing of Microsoft or Google
  • Custom CAPTCHA challenges blocking automated scanners
  • Adversary‑in‑the‑middle URLs capturing session cookies
  • Use of decoy landing pages based on geolocation
  • Telegram bots receiving harvested credentials

Recommended Actions

  • Strengthen MFA enforcement (e.g., enforce strong authentication methods, disable legacy protocols)
  • Deploy email filtering solutions with real‑time threat intelligence feeds to block Tycoon 2FA domains and URLs
  • Implement user training programs focused on sophisticated phishing tactics
  • Monitor for suspicious login patterns and unexpected token usage in cloud services
  • Enforce session token revocation policies and enable conditional access controls
  • Integrate security monitoring for custom CAPTCHA challenges and anomalous traffic

Suggested Tags

Phishing
MFA Bypass
PhaaS
Financial Services
Healthcare
Education
Government
Defense
Cybercriminal
Adversary-in-the-Middle
Credential Theft

Confidence Assessment

The analysis is based on publicly available information from Microsoft Threat Intelligence, the Malpedia actor page, and multiple reports describing Tycoon 2FA’s operation. While the technical capabilities of the kit are well documented, attribution details such as internal structure or state sponsorship remain unclear. Confidence in the kit’s usage patterns and TTPs is high; however, gaps persist regarding the actor's origin, long‑term operational longevity, and full extent of global reach.

ATT&CK Techniques

Persistence
1 technique
Reconnaissance
1 technique
Resource Development
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 9 Email Address 1 URL 10

References

  1. attack.mitre.org — Cited by web research for: T1518.002
  2. www.microsoft.com — Cited by web research for: Interception
  3. learn.microsoft.com — Cited by web research for: Tsunami
  4. www.elastic.co — Cited by web research for: Device code phishing
  5. www.proofpoint.com — Cited by web research for: Construction
  6. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet
  7. https://malpedia.caad.fkie.fraunhofer.de/actor/storm-1747 — Cited by AI analysis.
  8. https://www.microsoft.com/microsoft-threat-intelligence — Cited by AI analysis.

Intel Summary

47

Techniques

48

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Phishing
2FA Abuse
Financial Threat
MFA Bypass
PhaaS
Financial Services
Healthcare
Education
Government
Defense
Cybercriminal
Adversary-in-the-Middle
Credential Theft

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.