logo

Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA

ID: 9a839f0c-70a1-54b5-a2ef-b31d014673e8

STIX ID: report--9a839f0c-70a1-54b5-a2ef-b31d014673e8

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

A Tycoon 2FA Phishing-as-a-Service campaign has been observed combining phishing infrastructure with OAuth Device Code abuse to harvest Microsoft 365 access tokens (not passwords). The campaign leverages Trustifi click-tracking for reputation laundering, layered anti-analysis gating, a malicious delivery chain, and Node.js-based operator tooling from Alibaba Cloud (AS45102); the report provides IoCs (URLs, IPs, AppIds, user-agents, encryption key, MongoDB ObjectId) and recommends blocking device-code flows for end users, tightening OAuth consent, and enabling Continuous Access Evaluation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.