CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Tycoon2FA post-takedown resurgence

campaign · campaign:tycoon2fa-oauth-device-authorization-grant-microsoft-365-post-takedown

Tycoon2FA phishing-as-a-service resurgence after its March 2026 takedown, abusing the OAuth Device Authorization Grant against Microsoft 365.

Coverage
0
first 2026-05-18 → last –
no data
Latest activity
–
no entry about it yet
Peak priority
·
no entry about it yet
Targets
·
no sector or region stated
Sources cited
0
0 hosts

Story timeline

No published entries reference this entity yet.

Entries about Tycoon2FA post-takedown resurgence

No published entry is about this entity yet · an entry attaches by registry key, by the entity's name or a public alias in its title or body, or (for CVE entities) by exact CVE id.

explore in graph