Phishing Kits Hijack Microsoft 365 Tokens
Coverage from Security Affairs, BleepingComputer, and others

Cybercriminals are increasingly using device-code phishing, malicious OAuth applications, and adversary-in-the-middle techniques to obtain valid Microsoft 365 authentication tokens without directly stealing passwords or MFA codes.
Platforms including Tycoon2FA, ARToken, Forg365, and Kali365 package these methods into phishing-as-a-service offerings that support campaign delivery, token management, mailbox monitoring, and access to Microsoft cloud data. The activity matters because completed legitimate authentication can give attackers persistent access to Outlook, Teams, OneDrive, SharePoint, and connected single sign-on services.
The story broadens from device-code phishing tied mainly to token theft into a wider Microsoft identity-abuse ecosystem that now explicitly includes OAuth redirect abuse and adversary-in-the-middle phishing. It also places more emphasis on commercialized phishing services and their post-compromise capabilities against Microsoft cloud data and connected SSO apps.
The story now frames the activity less as a general wave of MFA-bypassing attacks and more as a packaged OAuth-abuse ecosystem built around phishing-as-a-service operators and affiliates. It also adds a clearer operational shift toward token-management, persistence, and post-compromise automation, including a reported disruption and recovery cycle for Tycoon2FA.
