[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fX8xWJcIdX71GLL8ltD-BbxNs6BizrBi6VJvfFcRlFYs":3},{"article":4,"iocs":36,"watch_terms":37},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":25},"c998512b-e6ad-4398-9fd2-2f29786b5283","Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing","tycoon-2fa-phishers-scatter-adopt-device-code-phishing-3458ed","In embracing device code phishing, attackers trick victims into handing over account access by using a service's legitimate new-device login flow.","The Tycoon 2FA phishing group has evolved its attack methodology, moving away from traditional two-factor authentication bypass techniques to exploit legitimate device code authentication flows. By deceiving victims into authorizing device login attempts, attackers gain account access without needing to compromise passwords or bypass 2FA directly. This represents a significant tactical shift in how the group operates.","Tycoon 2FA phishing group shifts to device code phishing attacks.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fthreat-intelligence\u002Ftycoon-2fa-hackers-device-code-phishing","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt70085bc1304b3cb3\u002F69e2855c41f7f85ddb368bc3\u002FQR_code-Harry_Wedzinga-Alamy.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-04-17T19:05:51+00:00","2026-04-17T22:00:08.599597+00:00",7,[18],{"name":19,"type":20},"Tycoon 2FA","threat_actor","2c8f44d4-b56e-47cf-9677-04f22c9ee78d",{"id":21,"icon":11,"name":23,"slug":24},"Identity & Access","identity-access",[26,31],{"category":27},{"id":28,"icon":11,"name":29,"slug":30},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":32},{"id":33,"icon":11,"name":34,"slug":35},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[],[]]