logo

Tycoon 2FA Operators Use OAuth Device Code Phishing to Bypass MFA

ID: 993fb459-1d19-520c-b11a-2f9562f0823a

STIX ID: report--993fb459-1d19-520c-b11a-2f9562f0823a

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Mayura Kathir

...
...

A late-April 2026 phishing campaign by Tycoon 2FA operators has evolved from credential capture to abusing Microsoft’s OAuth Device Authorization flow: victims are tricked into entering device codes on attacker-controlled pages which causes Microsoft to issue OAuth tokens directly to the attackers. The four-layer chain uses AES-encrypted payloads, extensive anti-analysis checks (including an ASN blocklist), a HumanCheck CAPTCHA decoy, Cloudflare Workers redirection and infrastructure on Alibaba Cloud (AS45102); defenders are advised to monitor device-code authentication events, suspicious user-agents (e.g., “node”, “undici”), restrict OAuth device flows, enforce strict consent policies, and enable CAE.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.