Tycoon2FA Rebuilds Into Microsoft 365 Device-Code Phishing

Tycoon2FA is back as a more resilient phishing platform, and the old assumption that a takedown or a legit-looking link makes the threat less serious no longer holds. It now uses OAuth device-code abuse against Microsoft 365, which can turn a successful phish into persistent account access through a rogue device. The kit was rebuilt after the March disruption, returned to regular activity, and added new obfuscation. In late April it was seen abusing Trustifi click-tracking URLs and Microsoft’s device authorization grant flow, with eSentire and earlier reporting from Abnormal Security, Push Security, and Proofpoint confirming the broader surge in device-code phishing. That combination matters because it defeats two common defenses at once: link reputation checks and password-focused awareness training. For Microsoft 365 teams, the risk is not just stolen credentials but an attacker-registered device that keeps access to mail, calendar, and cloud files.

Part of the PlainSec briefing for 2026-05-18

Sources