Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencecredential-access-methodidentity-authentication-vulnerabilitydefense-evasion-method

Tycoon2FA Adds OAuth Device-Code Phishing for Microsoft 365 Accounts

Updated 27d agoFirst seen May 18, 202610 sources

The Tycoon2FA phishing-as-a-service platform has resurfaced after a law enforcement disruption and is now using OAuth 2.0 device authorization grant abuse to compromise Microsoft 365 accounts protected by multifactor authentication. According to eSentire, the campaign begins with lure emails carrying Trustifi click-tracking URLs and guides victims through a multi-stage redirection chain, including a fake Microsoft CAPTCHA page, before directing them to Microsoft’s legitimate device login portal at microsoft.com/devicelogin.

Rather than exploiting a software flaw or directly bypassing MFA, the operation relies on social engineering to convince users to enter a device code and approve token issuance for an attacker-controlled device, giving the threat actor OAuth tokens for account access. Researchers said the kit retains much of the four-layer in-browser delivery chain seen in earlier Tycoon2FA variants while adding anti-analysis measures to hinder researchers and scanners; recommended defenses include disabling device-code flow where it is not needed, tightening OAuth consent controls, and increasing monitoring of Microsoft Entra logs.

Share:
Tycoon2FA Adds OAuth Device-Code Phishing for Microsoft 365 Accounts
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
May 27, 202628d ago

Researchers report Tycoon 2FA persistence via rogue Entra ID device registration

The new reporting said Tycoon 2FA supports post-compromise persistence by registering rogue devices in Microsoft Entra ID to obtain primary refresh tokens. This can allow attackers to maintain access even after stolen sessions are revoked, adding a new post-compromise capability beyond the previously documented phishing flow.

Tycoon 2FA AiTM Kit Bypasses MFA on Entra ID and Google Workspace Accounts
May 22, 20261mo ago

KnowBe4 highlights eSentire findings on evolved Tycoon 2FA campaign

A KnowBe4 report summarized eSentire's findings that the evolved Tycoon 2FA platform abuses legitimate Microsoft device login and social engineering rather than exploiting a software vulnerability or directly bypassing MFA. The report also reiterated that the operation had resumed after the earlier law enforcement takedown.

May 18, 20261mo ago

Researchers disclose anti-analysis features in updated Tycoon 2FA kit

Reporting on the updated kit said it included protections intended to block researchers, security vendors, and automated scanners. The disclosure added technical detail about how the phishing platform attempted to evade analysis while conducting device-code attacks.

Tycoon 2FA resumes operations with device-code phishing for Microsoft 365

eSentire reported that Tycoon 2FA resurfaced after the law enforcement disruption and added OAuth 2.0 device authorization grant abuse to target Microsoft 365 accounts. The campaign used lure emails with Trustifi click-tracking URLs, redirection and obfuscation layers, a fake Microsoft CAPTCHA page, and Microsoft's legitimate device login flow to obtain OAuth tokens from victims.

Apr 1, 20263mo ago

Tycoon 2FA variants documented again with similar delivery methods

Researchers noted that Tycoon 2FA variants were again documented in April 2026, with the latest campaign retaining a largely unchanged four-layer in-browser delivery chain. This indicates continuity in the kit's infrastructure and tradecraft.

Mar 4, 20264mo ago

Europol, Microsoft, and partners announce Tycoon 2FA takedown

Trend Micro reported that Europol, Microsoft, Trend Micro, and other collaborators halted Tycoon 2FA operations. The announcement publicly identified the coordinated disruption effort behind the phishing-as-a-service platform's earlier 2026 outage.

Europol, Microsoft, TrendAI™, and Collaborators Halt Tycoon 2FA Operations | Trend Micro (UK)
Jan 1, 20266mo ago

Tycoon 2FA disrupted by law enforcement takedown

The phishing-as-a-service operation was disrupted by a law enforcement takedown earlier in 2026. Later reporting described the disruption as recent before the kit resumed activity.

May 13, 20251y ago

Researchers analyze Tycoon 2FA defense-evasion mechanisms

A report published on 2025-05-13 examined Tycoon 2FA's defense-evasion and anti-analysis techniques, indicating the phishing kit was already incorporating mechanisms to hinder detection and investigation by that time. This adds an earlier technical milestone in the evolution of the platform's evasion tradecraft.

Evolution of Tycoon 2FA Defense Evasion Mechanisms
Apr 1, 20251y ago

Tycoon 2FA documented using a similar browser delivery chain

Researchers said the four-layer in-browser delivery chain seen in the latest Tycoon 2FA activity was largely unchanged from variants previously documented in April 2025. This establishes that core elements of the phishing kit were already in use by that time.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
4 linked
eSentireMicrosoft CorporationTrustifiBleepingComputer
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.