HomeSecurityTycoon 2FA: OAuth Device Code Phishing to Bypass MFA

Tycoon 2FA: OAuth Device Code Phishing to Bypass MFA

The cybercriminals behind the infamous Tycoon 2FA phishing kit are back with a significantly more sophisticated attack technique, which changes the data on Microsoft 365. The new version of the campaign no longer relies solely on stealing usernames and passwords, but leverages the OAuth Device Code Flow protocol to gain access to corporate accounts without directly stealing credentials.

Tycoon 2FA OAuth Device Code Phishing

This development is considered particularly worrying by cybersecurity experts, as it allows attackers to exploit legitimate Microsoft functions in a way that bypasses traditional detection and protection techniques.

Tycoon 2FA had already gained a reputation as one of the most effective phishing-as-a-service platforms of the past two years, allowing cybercriminals to bypass multi-factor authentication mechanisms through adversary-in-the-middle attacks. But now, the new tactic ups the ante even further.

See also: OpenAI confirms breach via TanStack supply chain attack

How the new password-free attack works

According to researchers at eSentire, Tycoon 2FA operators are now leveraging OAuth 2.0 Device Authorization Grant — a legitimate feature designed for devices like smart TVs or IoT systems that lack a full login environment.

In a normal process, the user receives a short code, visits an official login page, and authorizes the device to access their account. Tycoon 2FA takes advantage of this very process.

The attack begins with a convincing phishing email that presents itself as a Microsoft 365 voicemail notification. The message includes a link that leads the victim through a chain of redirects and fake security pages.

Finally, the victim is prompted to enter a password on the genuine microsoft.com/devicelogin page. That's where the trap lies: the MFA process completes normally and the user thinks they're securely logged in, but in reality they're authorizing a device controlled by the attacker.

See also: FlowerStorm phishing gang adopts virtual machine obfuscation

In this way, hackers obtain valid access tokens without having to intercept passwords or session cookies.

The new generation of phishing attacks exploits trust

The most dangerous element of the new campaign is that it relies almost exclusively on legitimate Microsoft services and real infrastructure. This makes the attacks much more difficult to detect by email gateways, antivirus tools, and anti-phishing protection mechanisms.

Attackers are also exploiting the legitimate Trustifi, using click-tracking links that have a good security reputation. Trustifi itself was not compromised, but cybercriminals are using the platform's credibility to bypass email security filters.

The campaign includes multiple layers of protection against researchers and analysis systems. Operators use encrypted payloads, anti-analysis techniques, fake Microsoft CAPTCHA pages, and blocking access for more than 230 security organizations.

Their goal is to ensure that only real victims reach the final stage of the attack.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Ghostwriter targets Ukrainian government with Geofenced PDF Phishing and Cobalt Strike

Tycoon 2FA: OAuth Device Code Phishing to Bypass MFA

A phishing kit that survived the Europol operation

Despite the major dismantling operation of Tycoon 2FA in March 2026 by Microsoft and Europol, its creators seem to have returned extremely quickly.

eSentire's research revealed that much of the original infrastructure remains largely unchanged. The same AES encryption keys, the same anti-debugging techniques, and the same backend paths continue to be used in the new attacks.

This indicates that the operators had kept full backups of the infrastructure and were able to restart their activity almost immediately after the takedown operation.

Analysts also found evidence of automation via Node.js tools and unusual user-agent strings such as “node” and “undici”, which appear in Microsoft Authentication Broker logs.

At the same time, the group appears to have transferred part of its hosting infrastructure to Alibaba Cloud, likely to avoid new business takedowns by Western authorities.

Tycoon 2FA: OAuth Device Code Phishing to Bypass MFA

What organizations should do immediately

Cybersecurity experts warn that OAuth phishing attacks will continue to increase in the coming years, as they allow traditional protection mechanisms without exploiting techniques or installing malware.

eSentire recommends that organizations disable OAuth Device Code Flows for regular users via Microsoft Entra Conditional Access policies. At the same time, companies should significantly limit the ability for user consent for third-party applications.

Enabling Continuous Access Evaluation is also considered critical, as it allows for the rapid revocation of access tokens in the event of a compromise.

Tycoon 2FA proves that modern phishing is no longer just about tricking users into revealing their passwords. Cybercriminals are now turning to abuse legitimate cloud authentication mechanisms, turning security platforms themselves into weapons of access.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS