Suspicious OAuth Device Code Sign-In to Authentication Broker via Tycoon 2FA

PremiumReviewedSigma · High · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-09-20
Updated
2026-09-20

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects a successful device code authentication against the Microsoft Authentication Broker application. Tycoon 2FA operators adopted OAuth device code phishing to trick users into authorizing attacker-controlled sessions and mint long-lived tokens for non-interactive Exchange and Graph access. Device code grants to the broker app are rare in normal use and indicate token theft.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious OfficeHome Sign-In With Axios User Agent via Tycoon 2FA Proxy
Suspicious AiTM Session Cookie Exfiltration to log_cookie Endpoint
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
Azure Audit Logs: Application URI Configuration Changes (AppAddress)
Suspicious Chrome Launched With Remote Debugging Port For Cookie Theft
Suspicious OAuth Sign-In Using Visual Studio Code Client and Auth Broker
Suspicious IAM Persistence and Privilege Escalation Actions
Suspicious AWS STS AssumeRoot Privilege Escalation To Member Account Root
Suspicious OAuth Device Code Sign-In to Authentication Broker via Tycoon 2FA
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.