Tycoon2FA takedown reshapes the phishing landscape

Tycoon2FA takedown reshapes the phishing landscape

Microsoft has reported a decline in several widely used phishing techniques, but warned that the drop does not signal a reduction in cybercriminal activity. Instead, attackers are adapting their methods, increasingly relying on more sophisticated social engineering campaigns and business email compromise (BEC) attacks.

Among the most significant threats observed during the reporting period was an automated BEC campaign that targeted more than 42,000 organizations in less than three hours. Microsoft also identified a separate, multi-stage phishing operation that combined nested email (EML) attachments, calendar invitations, and Microsoft’s authentication process to distribute malware while appearing legitimate.

To help organizations defend against phishing attacks, Microsoft recommends blocking emails containing known malicious links or suspicious subject lines, adopting passwordless authentication, and enabling multi-factor authentication (MFA) for accounts that still rely on passwords.

Tycoon2FA Disruption Reduced Traditional Phishing

Microsoft attributed much of the decline in traditional phishing activity to the disruption of the Tycoon2FA phishing-as-a-service platform. Following actions against the service, its operators were forced to rebuild parts of their infrastructure, including hosting services, domain registrations, and phishing delivery methods.

The impact was substantial. After phishing activity linked to Tycoon2FA declined by 15 percent in March and a further 22 percent in April, volumes dropped by 74 percent in May to approximately 1.5 million phishing messages. Activity fell by another 20 percent in June, reaching just 1.2 million messages—the lowest monthly total recorded in at least a year.

The disruption also significantly reduced phishing campaigns that relied on QR codes and fake CAPTCHA pages. In June, Tycoon2FA accounted for only 12 percent of QR code phishing activity and 14 percent of CAPTCHA-based attacks, suggesting many of its customers struggled to migrate to alternative phishing platforms.

Cybercriminals Shift to Microsoft Teams

While older phishing techniques declined, attackers quickly adopted new strategies. One notable trend was the growing misuse of Microsoft Teams as a social engineering platform.

Rather than sending traditional phishing emails immediately, attackers initiated conversations through Teams to build trust with potential victims before attempting to steal login credentials or deliver malicious software.

Microsoft observed Teams-based phishing steadily increasing throughout the second quarter of the year. Detected attacks rose by 19 percent between March and April, remained largely unchanged in May, and increased by another 10 percent in June.

The company also uncovered a highly automated business email compromise campaign that targeted more than 67,000 users. The operation relied on scripted emails, Amazon Simple Email Service (SES), and engagement tracking tools to increase effectiveness.

In a separate campaign affecting approximately 107,000 users, attackers exploited Microsoft’s authentication workflow alongside trusted cloud services—including Teams archive recordings and ICS calendar invitations—to disguise malware delivery as legitimate business communications.

Traditional Phishing Declines, But Threats Persist

Although phishing campaigns using QR codes and CAPTCHA verification pages declined sharply during the second quarter, business email compromise activity experienced significant fluctuations.

BEC attacks surged by 121 percent between March and April before falling again in May. Overall, Microsoft recorded approximately 9 million BEC attacks in March, decreasing to 3.9 million by June.

Similarly, QR code phishing attacks dropped from a peak of 18.7 million incidents in March to 8.3 million in June. CAPTCHA-based phishing also fell dramatically, declining from roughly 12 million attacks in March to 2.2 million in June.

Despite these shifts in attacker tactics, Microsoft emphasized that the most effective defenses remain largely unchanged.

The company advised organizations to strengthen email security by combining advanced filtering technologies with phishing-resistant authentication methods, including passkeys and phishing-resistant MFA, to minimize the risk of credential theft.

Microsoft also recommended enhancing Exchange Online Protection and Microsoft Defender for Office 365 by enabling features such as Safe Links and Zero-hour Auto Purge (ZAP), which automatically removes malicious emails from inboxes before recipients can open them.

Additionally, organizations are encouraged to move away from password-based authentication by implementing passwordless technologies such as Windows Hello, FIDO security keys, and Microsoft Authenticator.

The report concluded with a comprehensive list of indicators of compromise (IoCs) associated with the phishing campaigns observed during the quarter to assist security teams in identifying and responding to similar threats.

Add Your Comment