Activity timeline
Tycoon2FA appears in 2 tracked threats between and ; the busiest month was 2026-05 with 1 report.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1114 Email Collection — Collectionobserved in 2 of 2 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 2 of 2 tracked threats
- T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1528 Steal Application Access Token — Credential Accessobserved in 2 of 2 tracked threats
- T1530 Data from Cloud Storage — Collectionobserved in 2 of 2 tracked threats
- T1531 Account Access Removal — Impactobserved in 2 of 2 tracked threats
- T1550 Use Alternate Authentication Material — Lateral Movementobserved in 2 of 2 tracked threats
- T1566 Phishing — Initial Accessobserved in 2 of 2 tracked threats
- T1583 Acquire Infrastructure — Resource Developmentobserved in 2 of 2 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats
- T1078 Valid Accounts — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1090 Proxy — Command and Controlobserved in 1 of 2 tracked threats
- T1098 Account Manipulation — Persistenceobserved in 1 of 2 tracked threats
Tracked threats
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including PasskeysHIGH
- Tycoon 2FA Adopts OAuth 2.0 Device-Code Phishing — PhaaS Kit Hijacks Microsoft 365 Accounts via Microsoft Authentication Broker (AppId 29d9ed98) Through Trustifi Click-Tracking and Cloudflare Workers Delivery (eSentire TRU TL-2026-0522)HIGH