GitHub RadarBlue team tool
Repository with Domains Related to Tycoon2FA Phishing Infrastructure 18 stars.
Project links:Open GitHub projectBack to radar
A curated list of malicious domains and subdomains used in the Tycoon 2FA Phishing Campaign. This repository aims to support the security community by providing a centralized location for tracking and analyzing domains used in these attacks.
Tycoon 2FA is a sophisticated phishing-as-a-service (PhaaS) platform known for targeting enterprise users and bypassing multi-factor authentication (MFA) using adversary-in-the-middle (AitM) techniques. Attackers behind Tycoon 2FA deploy phishing pages that mimic legitimate login portals (e.g., Microsoft 365, Google Workspace) and use proxy-based interception to capture credentials and session tokens.