216.73.216.6

PhaaS the Secrets: The Hidden Ties Between Tycoon2FA and Dadsec's Operations

· Published 29/05/2025 16:10 · Modified 29/05/2025 19:37

Export JSON

Essential information

Published
29/05/2025 16:10
Modified
29/05/2025 19:37
Tags
2025-05-29 aitm credential-theft dadsec mfa bypass phishing-as-a-service tycoon2fa
Related entities
1 intrusion sets (apt), 12 techniques (mitre), 2 malware

Description

This analysis explores the connections between two (PhaaS) platforms: and . The investigation reveals shared infrastructure and operational similarities, suggesting a common origin or adaptation. The report details the evolving tactics of , including its use of Cloudflare Turnstile, anti-analysis techniques, and sophisticated phishing pages. Key findings include the rapid expansion of 's infrastructure, with thousands of new phishing pages detected since July 2024. The analysis also uncovers the platform's advanced features, such as capabilities and real-time credential interception. The report emphasizes the growing threat posed by PhaaS platforms and the need for continued vigilance and adaptation in cybersecurity defenses.

External references