ctipilot.ch

Tycoon2FA post-takedown resurgence

campaign · campaign:tycoon2fa-oauth-device-authorization-grant-microsoft-365-post-takedown

Tycoon2FA phishing-as-a-service resurgence after its March 2026 takedown, abusing the OAuth Device Authorization Grant against Microsoft 365.

Coverage timeline
0
first 2026-05-18 → last –
no data
Peak priority
no matching entries
Sources cited
0
0 hosts
Sections touched
0
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

No published entries reference this entity yet.

explore in graph

Entries about Tycoon2FA post-takedown resurgence

No published entry references this entity yet · entries match by registry key, by the entity's name or a public alias appearing in the entry title or body, or (for CVE entities) by exact CVE id.