logo

Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing

ID: fd3c2791-eb89-5e8a-b60e-b6b6ec72ab01

STIX ID: report--fd3c2791-eb89-5e8a-b60e-b6b6ec72ab01

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-04-17

Date Updated: 2026-04-22

Author: Nate Nelson

...
...

After a law-enforcement takedown of the Tycoon 2FA PhaaS, threat actors scattered to competitors such as Mamba 2FA, EvilProxy and Sneaky 2FA, driving sharp increases in phishing volume (millions of attacks per month) and an observable rise in device-code/OAuth phishing kits that reuse Tycoon artifacts and tactics — indicating a large-scale, active phishing threat that is evolving to bypass MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.