
ANY.RUN Exposes Tycoon 2FAโs Evolving Evasion Tactics to Beat Defenses in Corporate Phishing Attacks
DUBAI, DUBAI, UNITED ARAB EMIRATES, May 14, 2025 /EINPresswire.com/ -- ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, has released a detailed report on the evolution of Tycoon2FA, a phishing-as-a-service (PhaaS) kit targeting credentials of corporate clients of Microsoft 365.
๐๐ฒ๐๐จ๐จ๐ง๐๐ ๐: ๐๐๐ฏ๐๐ง๐๐๐ ๐๐ง๐ ๐๐ฏ๐จ๐ฅ๐ฏ๐ข๐ง๐ ๐๐ฏ๐๐ฌ๐ข๐จ๐ง ๐๐๐๐ญ๐ข๐๐ฌ
ANY.RUNโs research shows that Tycoon2FA has undergone significant updates over the past 6 months, incorporating a growing arsenal of evasion mechanisms. The newly introduced tactics help the threat evade endpoint protection, automated analysis, and corporate defenses. Key techniques include:
ยท ๐๐๐๐๐ผ๐บ ๐๐๐ฃ๐ง๐๐๐ ๐๐บ๐ฝ๐น๐ฒ๐บ๐ฒ๐ป๐๐ฎ๐๐ถ๐ผ๐ป: Transitioning from Cloudflare Turnstile to custom HTML5 canvas-based CAPTCHAs with randomized elements, enhancing stealth and blocking automated detection.
ยท ๐๐ผ๐บ๐ฝ๐น๐ฒ๐ ๐๐ฎ๐๐ฎ๐ฆ๐ฐ๐ฟ๐ถ๐ฝ๐ ๐ข๐ฏ๐ณ๐๐๐ฐ๐ฎ๐๐ถ๐ผ๐ป: Employs invisible Unicode characters (e.g., Hangul Filler) and encryption-based obfuscation, leveraging JavaScript Proxy objects to delay execution and evade static analysis.
ยท ๐๐ฑ๐๐ฎ๐ป๐ฐ๐ฒ๐ฑ ๐๐ป๐๐ถ-๐๐ฒ๐ฏ๐๐ด๐ด๐ถ๐ป๐ด ๐ฎ๐ป๐ฑ ๐๐ฟ๐ผ๐๐๐ฒ๐ฟ ๐๐ถ๐ป๐ด๐ฒ๐ฟ๐ฝ๐ฟ๐ถ๐ป๐๐ถ๐ป๐ด: Detects debugging environments (e.g., Selenium), manipulates clipboard content, and uses browser fingerprinting to tailor attacks.
ยท ๐๐ฒ๐ด๐ถ๐๐ถ๐บ๐ฎ๐๐ฒ ๐ฅ๐ฒ๐๐ผ๐๐ฟ๐ฐ๐ฒ ๐๐ฏ๐๐๐ฒ ๐ฎ๐ป๐ฑ ๐ฅ๐ฒ๐ฑ๐ถ๐ฟ๐ฒ๐ฐ๐๐ถ๐ผ๐ป ๐๐ต๐ฎ๐ถ๐ป๐: Utilizes legitimate CDNs for corporate logos and extended redirect chains to mask malicious infrastructure.
From basic obfuscation observed in October 2024 to recent additions like encryption-based obfuscation and custom fake page redirects noted in April and May 2025, Tycoon2FAโs continuous evolution underscores its ability to adapt and challenge even the most robust corporate defenses.
Read the full analysis on ANY.RUNโs Cybersecurity Blog.
๐๐จ๐ฐ ๐๐๐.๐๐๐ ๐๐๐ฅ๐ฉ๐ฌ ๐๐ฎ๐ฌ๐ข๐ง๐๐ฌ๐ฌ๐๐ฌ ๐๐จ๐ฎ๐ง๐ญ๐๐ซ ๐๐ฒ๐๐จ๐จ๐ง๐๐ ๐ ๐๐ญ๐ญ๐๐๐ค๐ฌ
ANY.RUNโs Interactive Sandbox equips SOC and DFIR teams with real-time analysis to detect and analyze Tycoon2FA campaigns. Businesses can extract Indicators of Compromise (IOCs), monitor phishing behaviors, and map attack tactics using the MITRE ATT&CK framework.
๐๐๐จ๐ฎ๐ญ ๐๐๐.๐๐๐
ANY.RUN is a trusted partner for over 15,000 organizations in finance, healthcare, retail, technology, and beyond, delivering advanced malware analysis and threat intelligence products. Its cloud-based Interactive Sandbox, Threat Intelligence Lookup, and TI Feeds enable businesses to analyze, investigate, and detect the latest malware and phishing campaigns to streamline triage, response, and proactive security.
The ANY.RUN team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
LinkedIn
YouTube
X

Distribution channels: Banking, Finance & Investment Industry, Companies, IT Industry, International Organizations, Technology
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
Submit your press release