Last Update: 09/22/2026 at 11:34 PM EST

Phishing Kits Hijack Microsoft 365 Tokens

Coverage from Security Affairs, BleepingComputer, and others

Phishing Kits Hijack Microsoft 365 Tokens topic image

Cybercriminals are increasingly using device-code phishing, malicious OAuth applications, and adversary-in-the-middle techniques to obtain valid Microsoft 365 authentication tokens without directly stealing passwords or MFA codes.

Platforms including Tycoon2FA, ARToken, Forg365, and Kali365 package these methods into phishing-as-a-service offerings that support campaign delivery, token management, mailbox monitoring, and access to Microsoft cloud data. The activity matters because completed legitimate authentication can give attackers persistent access to Outlook, Teams, OneDrive, SharePoint, and connected single sign-on services.

Looking Back
141 Day Timeline
Feb 19Mar 19Apr 16May 14Jun 11Jul 9
History
07/23/2026

The story broadens from device-code phishing tied mainly to token theft into a wider Microsoft identity-abuse ecosystem that now explicitly includes OAuth redirect abuse and adversary-in-the-middle phishing. It also places more emphasis on commercialized phishing services and their post-compromise capabilities against Microsoft cloud data and connected SSO apps.

07/23/2026

The story now frames the activity less as a general wave of MFA-bypassing attacks and more as a packaged OAuth-abuse ecosystem built around phishing-as-a-service operators and affiliates. It also adds a clearer operational shift toward token-management, persistence, and post-compromise automation, including a reported disruption and recovery cycle for Tycoon2FA.

All Articles9 articles
Additional9 articles · CI Score below 45
Security Affairs / Pierluigi Paganini
5/5/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
7/9/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Lawrence Abrams
7/3/2026 • Cybersecurity Tech (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
5/17/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
3/3/2026 • Personal Data & Identity • General
The Record / Jonathan Greig
5/22/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
3/31/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
4/3/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
2/19/2026 • Cybersecurity (Privacy-Relevant) • General