Tycoon 2FA Keeps Sessions After MFA Falls

Tycoon 2FA matters because MFA is not the end of the login. It steals the live session token after the victim finishes the prompt, so a password reset or a fresh MFA check can arrive after the attacker already has access. The takedown did not remove that advantage, because the operators came back quickly and shifted to OAuth Device Code phishing without changing the basic persistence model. Elastic Security Labs says Tycoon 2FA is still one of the most active AiTM PhaaS operations. It targets Microsoft Entra ID, Microsoft 365, and Google Workspace, and uses a real login flow in the middle to capture the authenticated session cookie or token. After the March 2026 disruption, eSentire saw campaigns in late April that mixed Tycoon tradecraft with OAuth Device Code phishing, showing the kit can adapt faster than a one-playbook defense. For identity teams, the threat is not just stolen passwords. A valid session token or OAuth grant can keep working after the phishing page is gone, which preserves mail and app access beyond the initial login event.

Part of the PlainSec briefing for 2026-05-26

Sources