Suspicious Tycoon Phishing-as-a-Service Credential Exfiltration Path (via proxy)

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-09-22
Updated
2026-09-22

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects HTTP POST requests to the /web6/info endpoint used by the Tycoon Phishing-as-a-Service platform to exfiltrate harvested credentials, cookies and MFA tokens from voicemail-themed phishing pages. The /web6/ path structure is served alongside XOR-obfuscated JavaScript and a Cloudflare Turnstile evasion prompt. This adversary-in-the-middle flow enables session and 2FA bypass.

Related detections9 linkedT1557 — drag to rearrange
Malicious Evilginx AiTM Phishing Proxy Default TLS Certificate
Malicious Tycoon 2FA AiTM Phishing WebSocket Channel
Suspicious AiTM Phishing Kit Session Validation Endpoint via Proxy
Suspicious OfficeHome Sign-In With Axios User Agent via Tycoon 2FA Proxy
Suspicious AWS AiTM Phishing Kit Endpoint Access via Proxy
Suspicious 1Phish Kit Session API Harvesting Credentials and OTP
Possible AiTM Phishing Sign-On Evaluation Denied by Okta FastPass
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Malicious TCP Session Hijacking via rshijack
Suspicious Tycoon Phishing-as-a-Service Credential Exfiltration Path (via proxy)
Pivot detection · T1557 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.