Tycoon 2FA Phishing Kit Analysis
Ανάλυση του Tycoon 2FA Phishing Kit

Bachelor Dissertation
Author
Katagis, Christos Michail
Καταγής, Χρήστος Μιχαήλ
Date
2026-09View/ Open
Keywords
Phishing ; PhaaS ; Phishing Kit ; AiTM ; Adversary-in-the-Middle ; Tycoon 2FA ; Tycoon2FAAbstract
Adversary-in-the-Middle (AiTM) Phishing-as-a-Service (PhaaS) platforms have industrialized credential theft and session
hijacking, allowing operators with minimal expertise to bypass multi-factor authentication (MFA) at scale. Tycoon2FA is
among the most widely deployed of these kits, yet much of its internal operation remains poorly documented and, in
places, mischaracterized in public reporting. This thesis provides an empirical, end-to-end analysis of the Tycoon2FA
attack flow, reconstructed from digital forensic artifacts left in the victim's browser during a representative set of real
world campaigns. The work maps how the kit uses dynamic single-page web frameworks to mirror legitimate login
interfaces while running anti-analysis logic in the background. It examines three layers of this logic in particular: client
side defenses against inspection, initial environment validation, and parameter-driven gateway routing, all of which
serve to frustrate automated analysis. To recover the kit's underlying behavior from heavily packed and protected
scripts, a progressive deobfuscation methodology is developed that isolates execution logic while preserving functional
integrity. The reconstructed sequences are then executed in a local instrumented analysis environment, enabling
controlled capture of network telemetry and observation of browser-state changes across the DOM, storage, and
cookies. The thesis then analyzes the live reverse-proxy relay established between the victim's browser and the
adversary infrastructure. It corrects a recurring claim in industry reporting about how this relay maintains connection
state, showing that the architecture depends on asynchronous HTTP request/response cycles rather than persistent
WebSocket channels. For the MFA bypass specifically, it documents the division of labor between synchronous
credential collection and recursive asynchronous polling loops used to monitor out-of-band approvals, across both
standard and federated identity environments. Finally, it traces the post-compromise lifecycle of session-cookie
harvesting and token injection. These findings are consolidated into a set of detection heuristics and threat-hunting
signatures that support proactive identification of active Tycoon2FA staging infrastructure through internet-wide asset
scanning.


