logo

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

ID: cbc6c05d-dc86-5697-a89f-24cbd2b8545e

STIX ID: report--cbc6c05d-dc86-5697-a89f-24cbd2b8545e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-05-17

Date Updated: 2026-05-17

Author: Bill Toulas

...
...

Tycoon2FA, a phishing-as-a-service platform, has resumed operations after a takedown and evolved to perform OAuth device-code phishing that leverages Trustifi click-tracking URLs, Cloudflare Workers, and obfuscated JavaScript to trick victims into authorizing attacker-controlled devices at microsoft.com/devicelogin, yielding OAuth tokens and full Microsoft 365 account access; the report details the attack flow, extensive anti-analysis defenses, mitigation recommendations, and published IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.