Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA
ID: 9a839f0c-70a1-54b5-a2ef-b31d014673e8
STIX ID: report--9a839f0c-70a1-54b5-a2ef-b31d014673e8
Feed Name: cybersecurityNews.com
A Tycoon 2FA Phishing-as-a-Service campaign has been observed combining phishing infrastructure with OAuth Device Code abuse to harvest Microsoft 365 access tokens (not passwords). The campaign leverages Trustifi click-tracking for reputation laundering, layered anti-analysis gating, a malicious delivery chain, and Node.js-based operator tooling from Alibaba Cloud (AS45102); the report provides IoCs (URLs, IPs, AppIds, user-agents, encryption key, MongoDB ObjectId) and recommends blocking device-code flows for end users, tightening OAuth consent, and enabling Continuous Access Evaluation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
