Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
…After this step, Microsoft issues OAuth access and refresh tokens to the attacker-controlled device. The Tycoon2FA phishing kit includes extensive protection against researchers and automated scanning, detecting Selenium, Puppeteer, Playwright, Burp…