logo

Resurgent Tycoon 2FA Adopts OAuth Device Code Phishing to Hijack Microsoft 365

ID: 38c3cb1d-5e66-5010-bbd6-2e424dccdfff

STIX ID: report--38c3cb1d-5e66-5010-bbd6-2e424dccdfff

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Ddos

...
...

eSentire’s Threat Response Unit reports the rapid resurgence of the Tycoon 2FA Phishing-as-a-Service platform in April 2026, which now abuses the OAuth Device Authorization Grant (microsoft.com/devicelogin) to obtain permanent access tokens rather than harvesting credentials. Attackers lure victims via realistic Microsoft 365 voicemail phishes that use legitimate click-tracking links to bypass gateways, instruct victims to enter operator-generated device codes into Microsoft’s real device-login flow, and then immediately use the issued tokens to query Office 365 and Microsoft Graph for mailbox and directory data. Forensics show the new variant retains four Tycoon code fingerprints (Check Domain logic, CryptoJS AES-CBC with hardcoded key/IV "1234567890123456", anti-debug timing loops, and Base64 XOR HTML wrapping), and the operator infrastructure was observed in Alibaba Cloud (ASN 45102). The report urges mitigations including disabling device code flows, restricting third-party app consent, and enforcing device compliance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.