- Sneaky 2FACompeting PhaaS platform gaining market share post-Tycoon disruption
- Tycoon 2FAPhishing-as-a-service platform disrupted by law enforcement; 330 domains seized in early March
- EvilProxyCompeting PhaaS platform gaining market share post-Tycoon disruption
- Mamba 2FACompeting PhaaS platform gaining market share post-Tycoon disruption
ThreatNoir Weekend Brief — April 18
Afternoon Review in IT Security — April 18, 2026
The cybersecurity landscape on April 18, 2026 reflects an increasingly fragmented threat ecosystem where disrupted platforms spawn new attack variants, critical infrastructure remains vulnerable to exploitation, and zero-day vulnerabilities continue to threaten enterprise security tools. Today's developments underscore the persistent challenges organizations face in maintaining robust defenses against evolving threats.
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
Following the disruption of the Tycoon 2FA platform, threat actors have begun reusing its tools across alternative phishing kits, demonstrating the resilience of the Phishing-as-a-Service ecosystem. The displacement of Tycoon 2FA from its dominant position has not eliminated the threat but rather distributed it across competing platforms including EvilProxy, Mamba 2FA, and Sneaky 2FA. Source: Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
This migration pattern reveals a critical vulnerability in the current approach to combating phishing infrastructure. Organizations relying solely on platform-specific defenses face significant risk as threat actors seamlessly transition between tools, maintaining operational capability despite law enforcement disruptions.
It Takes 2 Minutes to Hack the EU's New Age-Verification App
The European Union's newly developed age-verification application has been found to contain critical security flaws that can be exploited in approximately two minutes, raising serious questions about the adequacy of pre-release security testing. The vulnerability represents a significant gap in the vetting process for privacy-sensitive applications deployed at scale. Source: It Takes 2 Minutes to Hack the EU's New Age-Verification App
Beyond the age-verification application, the report also documents major data breaches affecting a gym chain and hotel giant, as well as a disruptive distributed denial-of-service attack targeting the Bluesky platform, illustrating the breadth of active threats across multiple sectors.
$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims
Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange previously sanctioned by both the United Kingdom and the United States, has suspended operations following a $13.74 million breach. The exchange attributed the attack to foreign intelligence agency involvement, citing operational hallmarks consistent with state-sponsored cyber activity. Source: $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims
The incident, which involved the theft of cryptocurrency holdings exceeding the reported figure, represents a significant intersection of sanctions enforcement and cyber operations. The involvement of malware families such as Conti and Hydra suggests sophisticated technical capabilities deployed in the operation.
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Huntress has disclosed that threat actors are actively exploiting three zero-day vulnerabilities in Microsoft Defender to achieve privilege escalation on compromised systems. The vulnerabilities, designated BlueHammer, RedSun, and UnDefend, were released by security researcher Chaotic Eclipse, with two remaining unpatched at the time of reporting. Source: Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
The active exploitation of these flaws, including CVE-2026-33825, demonstrates the speed at which threat actors weaponize newly disclosed vulnerabilities in critical security infrastructure. The continued unpatched status of two of the three vulnerabilities creates an extended window of exposure for organizations relying on Microsoft Defender as a primary security control.
The convergence of these threats across phishing infrastructure, government applications, financial systems, and enterprise security tools underscores the need for comprehensive, layered security strategies that account for both the sophistication and adaptability of modern threat actors.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- HydraDarknet market whose proceeds were processed by Garantex/Grinex
- ContiRansomware gang whose funds were laundered through Garantex/Grinex
- Microsoft Defender LPE vulnerability (BlueHammer), patched in Patch Tuesday
- UnDefendDenial-of-service vulnerability affecting Microsoft Defender definition updates, unpatched
- RedSunLocal privilege escalation vulnerability in Microsoft Defender, unpatched as of April 17, 2026
- BlueHammerLocal privilege escalation flaw in Microsoft Defender, exploited since April 10, 2026