Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

eSentire Threat Response Unit Documents Tycoon 2FA Phishing Variant Targeting Microsoft 365 in Late April 2026

Share the canonical public link.

Share as image

Steven Lim shared a KQL detection query for Microsoft Teams-based phishing campaigns that eSentire observed rising since early 2026. The attacks involve threat actors impersonating IT support or helpdesk personnel after email bombing to deceive users into granting remote access. Key details include eSentire's documentation of the Tycoon 2FA variant in late April 2026 where attackers direct victims to the real login page for MFA push approval leading to long-lived access tokens. Steven Lim posted the detection on May 19 2026 with 85 likes and 18 reposts.

Below validation threshold — auto-passed without scoring

Supporting evidence