Report: The Tycoon 2FA Phishing Kit Has Evolved
ID: f84c76f1-da3b-5068-abad-7d9fa0ee058a
STIX ID: report--f84c76f1-da3b-5068-abad-7d9fa0ee058a
Feed Name: KnowBe4 Blog
Threat Score
Tycoon 2FA, a phishing-as-a-service platform, has resumed operations and is actively conducting OAuth device code phishing attacks that trick users into granting OAuth tokens via Microsoft's legitimate device-login flow, enabling attackers to obtain access without exploiting technical vulnerabilities; the technique leverages social engineering to subvert MFA by changing what the MFA approval actually authorizes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
