End of the World’s Largest Phishing Service — Europol Dismantles Tycoon 2FA
End of the World’s Largest Phishing Service — Europol Dismantles Tycoon 2FA#### Europol dismantled a platform that bombarded over 500,000 organizations with phishing attacks every month and was responsible for 62% of all phishing attempts blocked by Microsoft in 2025. In Security Sunday, we will also look at CyberStrikeAI, which automatically infiltrated 600 Fortinet devices in 55 countries. Claude Opus 4.6, which revealed 22 vulnerabilities in Firefox. OpenAI Codex Security and the Iranian group MuddyWater, which was hiding unnoticed in the systems of large American companies.

An international operation coordinated by Europol has taken down Tycoon 2FA — one of the world’s largest phishing-as-a-service platforms, responsible for tens of millions of phishing messages every month.
The operation involved both law enforcement agencies and several major private technology companies — including Microsoft, Cloudflare, Proofpoint, Trend Micro, Coinbase, SpyCloud, and Intel 471. A total of 330 domains forming the criminal service’s core infrastructure were seized and taken offline, including administrative panels and phishing pages. Police operations took place in Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom.
Tycoon 2FA represented a new generation of so-called Phishing-as-a-Service (PhaaS) platforms. The subscription-based phishing kit first appeared in August 2023 and was sold via Telegram and Signal, starting at $120 for a 10-day access or $350 for a monthly subscription to the web admin panel.
What made Tycoon 2FA particularly dangerous was its ability to bypass MFA protection. Attackers hosted fraudulent login pages through a reverse proxy that intercepted the victim’s interaction with legitimate services such as Microsoft 365 or Gmail. Once the victim entered their credentials and confirmed the MFA prompt, the kit relayed the communication to the real service while simultaneously capturing sensitive authentication tokens.
Europol stated that the platform enabled thousands of cybercriminals to covertly access email and cloud accounts, hitting over 500,000 organizations worldwide every month — including schools, hospitals, and public institutions. The platform was linked to more than 64,000 phishing incidents and, by mid-2025, accounted for approximately 62% of all phishing attempts blocked by Microsoft. Geographic analysis of victim data showed the highest concentration of identified victims in the United States, with a large share of compromised email addresses tied to corporate domains, as attackers primarily targeted enterprise environments.
While the takedown of Tycoon 2FA is undoubtedly a major success, experts warn that the fight is far from over. Tycoon 2FA is not the only PhaaS platform capable of effectively bypassing MFA. Proofpoint data shows that in 2025, 99% of organizations encountered account takeover attempts.
Claude Discovered 22 Firefox Vulnerabilities; OpenAI Codex Security Identified 792 Critical Flaws
OpenAI has launched Codex Security, a security agent designed to automatically discover, validate, and propose fixes for vulnerabilities in code.
Codex Security is not an entirely new project. The tool was previously known internally as Aardvark and is now available as a research preview to all ChatGPT Pro, Enterprise, Business, and Edu plan customers through the Codex web interface, with the first month of use free of charge.
The beta testing results are impressive: during the last 30 days of the beta phase, the agent scanned more than 1.2 million commits from external repositories and identified 792 critical vulnerabilities and 10,561 high-severity security issues.
What sets Codex Security apart from traditional tools is its ability to operate within the context of a specific project. The system works in three phases: it first creates an editable threat model based on the repository structure, then validates identified issues in an isolated sandbox environment, and finally proposes fixes that account for the overall system context.
Meanwhile, Anthropic published the results of a collaboration with Mozilla, in which Claude Opus 4.6 discovered 22 security vulnerabilities in the Firefox browser in just two weeks. Of the total, 14 were classified as high severity, 7 as medium, and 1 as low.
The 14 high-severity vulnerabilities represent nearly one-fifth of all patched Firefox bugs for the entire year of 2025. In addition to the 22 CVEs, the analysis uncovered 90 further bugs, with the model identifying specific classes of logic errors that traditional fuzzing tools had not previously detected. All fixes were included in the Firefox 148 release.
CyberStrikeAI Breached 600 Firewalls Worldwide
Researchers from Team Cymru have released details on one of the largest automated attack campaigns in recent months. An AI-assisted campaign targeting Fortinet FortiGate devices leveraged an open-source platform called CyberStrikeAI.
The campaign was first documented by Amazon Threat Intelligence in February 2026. Between January and February 2026, the attacker systematically compromised more than 600 Fortinet FortiGate devices across 55 countries — without needing to exploit any zero-day vulnerabilities. All that was required was an exposed management interface and weak authentication; the AI handled the rest.
CyberStrikeAI is described as an “AI-native security testing platform written in Go” that integrates over 100 security tools. It includes an orchestration engine, a web dashboard, and a role-based system that allows even less experienced operators to run complex, automated campaigns at industrial scale. Attackers used AI to generate step-by-step attack plans, command sequences, and exploitation methodologies.
Team Cymru tracked a total of 21 unique IP addresses running CyberStrikeAI between January 20 and February 26, 2026, with servers concentrated primarily in China, Singapore, and Hong Kong.
Team Cymru warned that in the near future, defenders must be prepared for an environment in which tools like CyberStrikeAI — alongside other projects such as PrivHunterAI and InfiltrateX — significantly lower the barrier to entry for complex network exploitation.
Iranian Hacker Group MuddyWater Targets U.S. Networks
A group linked to Iran’s Ministry of Intelligence and Security (MOIS) has in recent weeks focused its efforts on the networks of several U.S. organizations. The campaign has been active since early February 2026, with targets including a U.S. bank, an airport, non-profit organizations in the U.S. and Canada, and an Israeli subsidiary of a U.S. software company supplying technology to the defense and aerospace sectors.
Researchers from Symantec’s and Broadcom’s Carbon Black Threat Hunter team found that the attackers had already established a firm foothold in the victims’ networks before the escalation of the military conflict.
The centerpiece of this operation is a previously unknown backdoor called Dindoor. Dindoor runs on Deno, a runtime environment for JavaScript and TypeScript. This is a notable technical choice — rather than using traditional compiled malware, the attackers deliberately selected a legitimate developer tool to complicate detection on endpoints.
In addition to Dindoor, a second tool was discovered on the networks of a U.S. airport and a non-profit organization: a Python-based backdoor named Fakeset. Fakeset was signed with certificates under the names “Amy Cherne” and “Donald Gay” — the certificate under the name Donald Gay was previously used to sign the malware Stagecomp and Darkcomp, which security firms Google, Microsoft, and Kaspersky had earlier attributed to MuddyWater.
The group has previously demonstrated the ability to exploit compromised cameras in direct support of its operations. In May 2025, MuddyWater took control of a security camera recording server in Jerusalem, and Iranian forces shortly afterward launched a missile strike on the city.
Security Sunday — SYSNETSHIELD