people · May 20, 2026
eSentire Threat Research Unit Documents Tycoon 2FA OAuth Device-Code Phishing Variant
Share the canonical public link.
eSentire Threat Research Unit documented Tycoon 2FA operators adopting OAuth device-code phishing in late April 2026 following March 2026 law-enforcement takedown. The variant routes victims through a four-layer obfuscated delivery chain to complete MFA at the real Microsoft login page and hand over long-lived access tokens. Every business running Microsoft 365 remains in scope without needing a CVE or misconfiguration. Push Security reports a 37x increase in device-code phishing this year across at least 10 PhaaS platforms.