people · May 21, 2026
eSentire Threat Response Unit Documents Tycoon 2FA Phishing Variant Targeting Microsoft 365 in Late April 2026
Share the canonical public link.
Steven Lim shared a KQL detection query for Microsoft Teams-based phishing campaigns that eSentire observed rising since early 2026. The attacks involve threat actors impersonating IT support or helpdesk personnel after email bombing to deceive users into granting remote access. Key details include eSentire's documentation of the Tycoon 2FA variant in late April 2026 where attackers direct victims to the real login page for MFA push approval leading to long-lived access tokens. Steven Lim posted the detection on May 19 2026 with 85 likes and 18 reposts.