March 27, 2024, 7:12 p.m. | Farah Iyer

Security Boulevard securityboulevard.com

This blog details how Obsidian detects and blocks the latest version of Tycoon, an adversary-in-the-middle (AiTM), Phishing-as-a-Service (PhaaS) platform that leverages a reverse proxy to intercept and replay credentials and MFA prompts. This new version of Tycoon has recently received press from Forbes [1], Dark Reading [2], TechRadar [3], and others. Background Sekoia wrote a […]


The post Detecting & Blocking Tycoon’s latest AiTM Phishing Kit appeared first on Obsidian Security.


The post Detecting & Blocking Tycoon’s latest AiTM …

adversary adversary-in-the-middle aitm aitm phishing aitm phishing kit as-a-service blocking blog credentials dark developer field notes featured forbes intercept kit latest mfa obsidian phaas phishing phishing-as-a-service phishing kit platform press product spotlights prompts proxy replay reverse reverse proxy saas security security guidance service tycoon version

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States