Tycoon2FA Expands to Device-Code Phishing Targeting Microsoft 365

1 min read
Source: BleepingComputer
Tycoon2FA Expands to Device-Code Phishing Targeting Microsoft 365
Photo: BleepingComputer
TL;DR Summary

A new Tycoon2FA variant uses device-code phishing via a Trustifi click-tracking URL to hijack Microsoft 365 accounts by steering victims to the legitimate device-login flow at microsoft.com/devicelogin, granting attackers OAuth tokens and access to email, calendar, and files. After a takedown, the kit resurfaced with obfuscation and new delivery chains, prompting defenders to disable the device-code flow when not needed, restrict OAuth permissions, enable Continuous Access Evaluation, and monitor Entra logs for deviceCode activity and related IoCs.

Share this article

Reading Insights

Total Reads

0

Unique Readers

9

Time Saved

4 min

vs 5 min read

Condensed

91%

87877 words

Want the full story? Read the original article

Read on BleepingComputer