Threats · 121 days ago
Tycoon2FA is back as a more resilient phishing platform, and the old assumption that a takedown or a legit-looking link makes the threat less serious no longer holds. It now uses OAuth device-code abuse against Microsoft 365, which can turn a successful phish into persistent account access through a rogue device.
The kit was rebuilt after the March disruption, returned to regular activity, and added new obfuscation. In late April it was seen abusing Trustifi click-tracking URLs and Microsoft’s device authorization grant flow, with eSentire and earlier reporting from Abnormal Security, Push Security, and Proofpoint confirming the broader surge in device-code phishing.
That combination matters because it defeats two common defenses at once: link reputation checks and password-focused awareness training. For Microsoft 365 teams, the risk is not just stolen credentials but an attacker-registered device that keeps access to mail, calendar, and cloud files.
1 source covering this story
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts.
Part of the PlainSec briefing for 2026-05-18