Tycoon2FA PhaaS post-March-2026-takedown — OAuth Device Authorization Grant abuse on Microsoft 365
campaign · item:tycoon2fa-oauth-device-authorization-grant-microsoft-365-post-takedown
Coverage timeline
3
first 2026-05-18 → last 2026-05-18
Briefs
1
1 distinct
Sources cited
7
4 hosts
Sections touched
3
action_items, deep_dive, tldr
Co-occurring entities
0
no co-occurrence
2026-05-183 appearances2026-05-18
Story timeline
- 2026-05-18CTI Daily Brief — 2026-05-18
- 2026-05-18CTI Daily Brief — 2026-05-18
- 2026-05-18CTI Daily Brief — 2026-05-18
Where this entity is cited
- tldr1
- deep_dive1
- action_items1
Source distribution
- attack.mitre.org4 (57%)
- bleepingcomputer.com1 (14%)
- blog.sekoia.io1 (14%)
- esentire.com1 (14%)
All cited sources (7)
- esentire.comprimaryinlineeSentire TRU, 2026-05-12https://www.esentire.com/blog/tycoon-2fa-operators-adopt-oauth-device-code-phishing
- attack.mitre.orginline`T1078.004`https://attack.mitre.org/techniques/T1078/004/
- attack.mitre.orginline`T1528`https://attack.mitre.org/techniques/T1528/
- attack.mitre.orginline`T1550.001`https://attack.mitre.org/techniques/T1550/001/
- attack.mitre.orginline`T1566.002`https://attack.mitre.org/techniques/T1566/002/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-17https://www.bleepingcomputer.com/news/security/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing/
- blog.sekoia.ioinlineSekoia's reference analysishttps://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/
Items in briefs about Tycoon2FA PhaaS post-March-2026-takedown — OAuth Device Authorization Grant abuse on Microsoft 365
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.