Briefing

Phishing‑as‑a‑Service Platforms Hijack Hundreds of Microsoft 365 Accounts

security
by Bill Toulas · Cloudflare

Patch: Disable OAuth device‑code flow on Microsoft 365 accounts and enforce Continuous Access Evaluation to mitigate Tycoon2FA device‑code phishing.

What to do now

Patch: Disable OAuth device‑code flow on Microsoft 365, enforce CAE, and audit Entra logs for deviceCode activity.

Summary

In early 2026 a new wave of phishing‑as‑a‑service (PhaaS) platforms began targeting Microsoft 365 users by exploiting the device‑login flow. EvilTokens, launched in February, quickly compromised more than 340 organizations across five countries. The attackers use a short code entry page that mimics the legitimate microsoft.com/devicelogin site. Victims, trusting the familiar interface, enter their multi‑factor authentication (MFA) verification code, which the attackers then capture and use to gain full access to the victim’s Microsoft 365 environment. Security researchers discovered the campaign after five weeks of operation, noting that the rapid spread demonstrates the effectiveness of PhaaS models in delivering large‑scale phishing attacks.

Another platform, Tycoon2FA, has been reported to employ a similar device‑code phishing technique, hijacking Microsoft 365 accounts by luring users into submitting their MFA codes on a counterfeit login page. While specific details of Tycoon2FA’s reach are not yet fully disclosed, the pattern mirrors EvilTokens’ approach, underscoring a broader trend of attackers exploiting user trust in the device‑login process.

The attacks highlight a critical vulnerability in the way many organizations implement MFA: the reliance on the device‑login flow without additional verification steps. Microsoft and security experts advise that organizations enforce stricter MFA verification, such as requiring a second factor that cannot be captured via a phishing page, and monitor for suspicious login patterns. The incidents also call for increased user education about phishing risks and the importance of verifying the authenticity of login pages before entering sensitive information.

Key changes

  • Tycoon2FA now supports device‑code phishing via OAuth 2.0 device authorization grant flows.
  • The kit uses Trustifi click‑tracking URLs, Cloudflare Workers, and obfuscated JavaScript to deliver a fake Microsoft CAPTCHA page.
  • It captures the OAuth device code entered by the victim and obtains access and refresh tokens for a rogue device.
  • The delivery chain includes Selenium, Puppeteer, Playwright, Burp Suite, VPNs, sandboxes, AI crawlers, and cloud providers, with a 230‑vendor blocklist.
  • eSentire recommends disabling OAuth device‑code flow, restricting consent permissions, requiring admin approval for third‑party apps, enabling CAE, and enforcing compliant device access policies.
  • Monitoring Entra logs for deviceCode authentication, Microsoft Authentication Broker usage, and Node.js user agents is advised.

Affects

enterprise internal

Source angles · 2 perspectives

Bleeping Computer
Independent angle

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

Open
The Hacker News
Independent angle

EvilTokens Phishing‑as‑a‑Service Compromises 340+ Microsoft 365 Organizations

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting