Researchers from TrendAI have been tracking the infrastructure, as well as the campaigns and operator behaviors that can be linked to Tycoon 2FA to build a clearer picture of how its services was being used at scale.
By November 2025, TrendAI had collected enough data to link the operation to an actor using the monikers “SaaadFridi” and “Mr_Xaad”, likely the developer/operator of Tycoon 2FA. Historical activity showed this actor previously focused on web defacements before moving into building and running this phishing toolkit. Intelligence gathered by TrendAI also included details on tooling, infrastructure, and activity patterns, which was shared with Europol to support law enforcement action.
Read more…
Source: Trend Micro
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
September 3, 2026
We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities. Read more… Source: Palo Alto Unit 42 Sign up for the Cyber Security Review Newsletter The latest cyber security news and insights delivered ...
- 2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm
September 3, 2026
Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people – both patients and employees. In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. ...
- SonicWall’s SMA1000 boxes under active attack again
September 2, 2026
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks. So, get to applying those hotfixes, says SonicWall. There are no ...
- 153M+ driver’s licenses for sale on new dark web platform
September 2, 2026
A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports. The trove of driver’s license scans reported by ...
- Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
September 1, 2026
While monitoring Mirage Kitten activity, Kaspersky researchers uncovered a previously undocumented malware family that we dubbed NodeRabbit. The researchers identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia. NodeRabbit is a cross-platform remote access ...
- Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing
September 1, 2026
Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as “OAuth consent phishing.” Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted ...
