The Tycoon2FA phishing-as-a-service platform has resurfaced after a law enforcement disruption and is now using OAuth 2.0 device authorization grant abuse to compromise Microsoft 365 accounts protected by multifactor authentication. According to eSentire, the campaign begins with lure emails carrying Trustifi click-tracking URLs and guides victims through a multi-stage redirection chain, including a fake Microsoft CAPTCHA page, before directing them to Microsoft’s legitimate device login portal at microsoft.com/devicelogin.
Rather than exploiting a software flaw or directly bypassing MFA, the operation relies on social engineering to convince users to enter a device code and approve token issuance for an attacker-controlled device, giving the threat actor OAuth tokens for account access. Researchers said the kit retains much of the four-layer in-browser delivery chain seen in earlier Tycoon2FA variants while adding anti-analysis measures to hinder researchers and scanners; recommended defenses include disabling device-code flow where it is not needed, tightening OAuth consent controls, and increasing monitoring of Microsoft Entra logs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
The new reporting said Tycoon 2FA supports post-compromise persistence by registering rogue devices in Microsoft Entra ID to obtain primary refresh tokens. This can allow attackers to maintain access even after stolen sessions are revoked, adding a new post-compromise capability beyond the previously documented phishing flow.
A KnowBe4 report summarized eSentire's findings that the evolved Tycoon 2FA platform abuses legitimate Microsoft device login and social engineering rather than exploiting a software vulnerability or directly bypassing MFA. The report also reiterated that the operation had resumed after the earlier law enforcement takedown.
Reporting on the updated kit said it included protections intended to block researchers, security vendors, and automated scanners. The disclosure added technical detail about how the phishing platform attempted to evade analysis while conducting device-code attacks.
eSentire reported that Tycoon 2FA resurfaced after the law enforcement disruption and added OAuth 2.0 device authorization grant abuse to target Microsoft 365 accounts. The campaign used lure emails with Trustifi click-tracking URLs, redirection and obfuscation layers, a fake Microsoft CAPTCHA page, and Microsoft's legitimate device login flow to obtain OAuth tokens from victims.
Researchers noted that Tycoon 2FA variants were again documented in April 2026, with the latest campaign retaining a largely unchanged four-layer in-browser delivery chain. This indicates continuity in the kit's infrastructure and tradecraft.
Trend Micro reported that Europol, Microsoft, Trend Micro, and other collaborators halted Tycoon 2FA operations. The announcement publicly identified the coordinated disruption effort behind the phishing-as-a-service platform's earlier 2026 outage.
The phishing-as-a-service operation was disrupted by a law enforcement takedown earlier in 2026. Later reporting described the disruption as recent before the kit resumed activity.
A report published on 2025-05-13 examined Tycoon 2FA's defense-evasion and anti-analysis techniques, indicating the phishing kit was already incorporating mechanisms to hinder detection and investigation by that time. This adds an earlier technical milestone in the evolution of the platform's evasion tradecraft.
Researchers said the four-layer in-browser delivery chain seen in the latest Tycoon 2FA activity was largely unchanged from variants previously documented in April 2025. This establishes that core elements of the phishing kit were already in use by that time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceelastic.co
Open sourceblog.knowbe4.com
Open sourcescworld.com
Open sourcecloudflare.com
Open sourceblogs.microsoft.com
Open sourcecloudflare.com
Open sourceany.run
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.