Threats & Adversaries · Phishing / BEC

Tycoon2FA Rebuilds Into Microsoft 365 Device-Code Phishing

Tycoon2FA is back as a more resilient phishing platform, and the old assumption that a takedown or a legit-looking link makes the threat less serious no longer holds. It now uses OAuth device-code abuse against Microsoft 365, which can turn a successful phish into persistent account access through a rogue device.

The kit was rebuilt after the March disruption, returned to regular activity, and added new obfuscation. In late April it was seen abusing Trustifi click-tracking URLs and Microsoft’s device authorization grant flow, with eSentire and earlier reporting from Abnormal Security, Push Security, and Proofpoint confirming the broader surge in device-code phishing.

That combination matters because it defeats two common defenses at once: link reputation checks and password-focused awareness training. For Microsoft 365 teams, the risk is not just stolen credentials but an attacker-registered device that keeps access to mail, calendar, and cloud files.

1 source · May 17

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-05-17

Every edition of this story: Tycoon2FA Rebuilds Into Microsoft 365 Device-Code Phishing

More from today