PULSE NAME
Major Cyber Attacks in August 2025: 7-Stage Tycoon2FA Phishing, New ClickFix Campaign, and Salty2FA.
WHITE PetrP.73 2025-08-27 Modified: 2025-09-26
29
IOCs
MEDIUM VOLUME
In August 2025, the cyber landscape experienced a notable increase in sophisticated phishing campaigns, highlighted by the emergence of the Tycoon2FA framework, which employs a unique seven-stage phishing attack strategy. This approach significantly deviates from conventional phishing techniques, enhancing its effectiveness by incorporating elements such as CAPTCHAs, button-hold checks, and validation screens. Each phase of the Tycoon2FA execution is meticulously crafted to exhaust the user's defenses, effectively circumventing automated security measures. By the time victims reach the final phishing panel, many security systems have already been compromised or bypassed.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Rhadamanthys ClickFix NetSupport MSI Storm-1575 Tycoon2FA
Indicators of Compromise (29)
All URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL http://marketplace24ei.ru// 2025-08-27
URL http://marketplace24ei.ru/790628.php 2025-08-27
URL http://telephony.nexttradeitaly.com/SSSuWBTmYwu/ 2025-08-27
domain culturabva.es 2025-08-27
domain dvlhpbxlmmi.es 2025-08-27
domain filecloudonline.com 2025-08-27
domain flaxergaurds.com 2025-08-27
domain innovationsteams.com 2025-08-27
domain loanauto.cloud 2025-08-27
domain marketplace24ei.ru 2025-08-27
domain pyfao.es 2025-08-27
domain spaijo.es 2025-08-27
domain temopix.com 2025-08-27
domain vnositel-bg.com 2025-08-27
domain wetotal.net 2025-08-27
domain yurikamome.com 2025-08-27
domain zerontwoposh.live 2025-08-27
hostname telephony.nexttradeitaly.com 2025-08-27
domain culturabva.es 2025-08-27
domain dvlhpbxlmmi.es 2025-08-27
domain filecloudonline.com 2025-08-27
domain pyfao.es 2025-08-27
domain spaijo.es 2025-08-27
domain vnositel-bg.com 2025-08-27
domain flaxergaurds.com 2025-08-27
domain loanauto.cloud 2025-08-27
domain temopix.com 2025-08-27
domain wetotal.net 2025-08-27
domain zerontwoposh.live 2025-08-27