#aitm

2025-04-03

This week, we encountered a new phishing campaign utilizing the Tycoon 2FA Phishing-as-a-Service (PhaaS) to bypass multifactor authentication (MFA).

The RDGA domains have Russian TLDs but are hosted on CloudFlare infrastructure. We have been seeing them use shared infrastructure for a few months now, definitely trying to make detection more challenging. They continue to obfuscate every piece of code but have updated their verification page. Previously, we always saw their custom Cloudflare Turnstile page, but now they also use a new captcha challenge, as shown below.(You can also check it here urlscan.io/result/0195ed8b-7a4 )

Their old Cloudflare Turnstile page seems to still be their favorite, even though they now change their message more frequently: "Checking response before request" or "Tracking security across platform" are some of the new messages they use.

Here is a sample of the hundreds of domains we are detecting:
womivor[.]ru
nthecatepi[.]ru
toimlqdo[.]ru
dantherevin[.]ru
xptdieemy[.]ru

#dns #domains #phishing #AitM #PhaaS #tycoon #scam #cybercrime #threatintelligence #cybersecurity #infoblox #infobloxthreatintel #infosec #2MFABypass

New verification page associated with Tycoon PhaaSCloudflare verification page associated with Tycoon PhaaS
Radio AzureusRadioAzureus
2025-03-21

@ErikvanStraten@infosec.exchange

Dankjewel voor deze verhelderende uitleg. Ik heb er niet bij stilgestaan dat door Cloudflare grote blokken van het internet letterlijk kunnen worden uitgeschakeld, door simpelweg een script te draaien

2025-02-28

Wenn die Phishing-Attacke zuschlägt… 🎣

Insbesondere mit den neuen AitM-Attacken, welche die Multi-Faktor-Authentifizierung umgehen können, ist das Phishing wieder in aller Munde ⚠️

Was hinter diesen neuartigen Angriffen steckt und wie Ihr Euch dagegen schützen könnt, erfahrt Ihr auf unserem Blog ➡️ sohub.io/158j

2025-02-13

Microsoft 365: Prävention und Reaktion bei AiTM Phishing-Attacken 🛡

Weitere Informationen: sohub.io/pw32

Claus Cramon Houmannclaushoumann
2024-10-24

And as the final presenter before lunch on day 3, @Jacob is now on stage talking about protecting against attacks at scale with - at @hack_lu !!

Martin Boller 🇬🇱 🇺🇦 :tux: :freebsd: :windows: :mastodon:itisiboller@infosec.exchange
2024-10-24

Up soon:
"From 0 to millions: Protecting against AitM phishing at scale"

@hack_lu #hacklu2024 #canaries #Thinkst #HoneyEverything #TTPs #AiTM #Deception #DetectionEngineering

John Leonardjohnleonard
2024-07-04

Passkey implementations by Google, Amazon, Microsoft vulnerable to AitM attacks, research

Attackers can proxy login pages, removing mention of passkeys and prompting users to resort to passwords, finds eSentire.

computing.co.uk/news/4331630/p

young man yells at the cloudbamboombibbitybop
2024-03-29

"Adversary In The Middle" feels like an unnecessary and clunky change. Let's at least keep the alliteration if we're gonna change it, guys. "Man in the middle," that shit rolls off the tongue.

"Threat in the middle"?
"Manipulator in the middle"?
"Enemy in the in-between"?

We can do better.





PCFIXIT Business IT Solutionspcfixit
2024-03-26

Hackers are using this new phishing technique to steal Gmail and Microsoft 365 accounts.

2FA - Adversary-in-the-Middle () and Phishing-as-a-Service ()
A sophisticated new phishing-as-a-service platform called “Tycoon 2FA” is gaining popularity among cybercriminals due to its ability to bypass multi-factor authentication and steal login credentials for Microsoft 365 and Gmail accounts.

Ongoing End-User Security awareness training is paramount in educating and arming your tea

Andréa Raquel YoungSugarFreeCoach
2023-12-25

🎶🎵 Kickstart your week with inspiring music & empowerment on The Lifestyle Show w/ ! 🎵🎶 A dose of motivation, , and wisdom. 💪💡 Don't miss this exciting podcast episode! 🎙️🔥 ✨

Andréa Raquel YoungSugarFreeCoach
2023-12-18

🎶🎵 Kickstart your week with inspiring music & empowerment on The Lifestyle Show w/ ! 🎵🎶 A dose of motivation, , and wisdom. 💪💡 Don't miss this exciting podcast episode! 🎙️🔥 ✨

Sources & Methodssrcmtd@infosec.exchange
2023-12-15

Kicking off The Finished Product with a threat report on Evilginx, an open source AiTM phishing tool in active use #CTI #phishing #AiTM sourcesmethods.com/evilginx-ph

Andréa Raquel YoungSugarFreeCoach
2023-12-11

Unlock the power of self-actualization and elevate your frequency. Tune in for insights. Dive into a transformative exploration of personal growth and conscious living w/ 🌟

Empowerment 💪

📚
🚀
🌱
🧘♂️
📖
🔆
🎵
🌌
🦉
🌍

Andréa Raquel YoungSugarFreeCoach
2023-12-11

🎶🎵 Kickstart your week with inspiring music & empowerment on The Lifestyle Show w/ ! 🎵🎶 A dose of motivation, , and wisdom. 💪💡 Don't miss this exciting podcast episode! 🎙️🔥 ✨

Andréa Raquel YoungSugarFreeCoach
2023-12-04

🎶🎵 Kickstart your week with inspiring music & empowerment on The Lifestyle Show w/ ! 🎵🎶 A dose of motivation, , and wisdom. 💪💡 Don't miss this exciting podcast episode! 🎙️🔥 ✨

Andréa Raquel YoungSugarFreeCoach
2023-11-27

🎶🎵 Kickstart your week with inspiring music & empowerment on The Lifestyle Show w/ ! 🎵🎶 A dose of motivation, , and wisdom. 💪💡 Don't miss this exciting podcast episode! 🎙️🔥 ✨

Andréa Raquel YoungSugarFreeCoach
2023-11-20

🎶🎵 Kickstart your week with inspiring music & empowerment on The Lifestyle Show w/ ! 🎵🎶 A dose of motivation, , and wisdom. 💪💡 Don't miss this exciting podcast episode! 🎙️🔥 ✨

Andréa Raquel YoungSugarFreeCoach
2023-11-13

🎶🎵 Kickstart your week with inspiring music & empowerment on The Lifestyle Show w/ ! 🎵🎶 A dose of motivation, , and wisdom. 💪💡 Don't miss this exciting podcast episode! 🎙️🔥 ✨

Andréa Raquel YoungSugarFreeCoach
2023-11-06

🎶🎵 Kickstart your week with inspiring music & empowerment on The Lifestyle Show w/ ! 🎵🎶 A dose of motivation, , and wisdom. 💪💡 Don't miss this exciting podcast episode! 🎙️🔥 ✨

Andréa Raquel YoungSugarFreeCoach
2023-11-01

Grand Rising - AI Besties 🧘🏾‍♀️🐆🐉💨
wisdom.app/tl/vyA2

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst