Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
ID: cbc6c05d-dc86-5697-a89f-24cbd2b8545e
STIX ID: report--cbc6c05d-dc86-5697-a89f-24cbd2b8545e
Feed Name: Bleeping Computer
Tycoon2FA, a phishing-as-a-service platform, has resumed operations after a takedown and evolved to perform OAuth device-code phishing that leverages Trustifi click-tracking URLs, Cloudflare Workers, and obfuscated JavaScript to trick victims into authorizing attacker-controlled devices at microsoft.com/devicelogin, yielding OAuth tokens and full Microsoft 365 account access; the report details the attack flow, extensive anti-analysis defenses, mitigation recommendations, and published IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
