Threats · 121 days ago

Tycoon2FA Rebuilds Into Microsoft 365 Device-Code Phishing

Tycoon2FA is back as a more resilient phishing platform, and the old assumption that a takedown or a legit-looking link makes the threat less serious no longer holds. It now uses OAuth device-code abuse against Microsoft 365, which can turn a successful phish into persistent account access through a rogue device.

The kit was rebuilt after the March disruption, returned to regular activity, and added new obfuscation. In late April it was seen abusing Trustifi click-tracking URLs and Microsoft’s device authorization grant flow, with eSentire and earlier reporting from Abnormal Security, Push Security, and Proofpoint confirming the broader surge in device-code phishing.

That combination matters because it defeats two common defenses at once: link reputation checks and password-focused awareness training. For Microsoft 365 teams, the risk is not just stolen credentials but an attacker-registered device that keeps access to mail, calendar, and cloud files.

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-05-18

Editions

Related stories