Suspicious Google Workspace OAuthLogin From Node.js Client via Tycoon 2FA

PremiumReviewedSigma · Medium · v1
Product
gws
Service
google_workspace.login
Author
HuntRule
Published
2026-09-16
Updated
2026-09-16

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Discovery

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects Google Workspace OAuth token issuance for the reserved client that requests the accounts OAuthLogin scope from Node.js user agents as used in Tycoon 2FA adversary in the middle attacks in Elastic research. This pattern reflects an attacker minting long lived login tokens after phishing the session rather than legitimate browser authentication.

Related detections9 linkedT1550.001 — drag to rearrange
Suspicious AWS Console Phishing MFA Relay Endpoints
Suspicious AWS AiTM Phishing Kit Endpoint Access via Proxy
Malicious GCP Service Account Backdoor via serviceAccountTokenCreator Grant
Suspicious GCP Service Account Impersonation via GenerateAccessToken
Suspicious Azure AD MFA Fatigue Repeated Push Denials
Suspicious AWS Role Assumption via Cognito Web Identity
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
Suspicious Google Workspace OAuthLogin From Node.js Client via Tycoon 2FA
Pivot detection · T1550.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.