logo

State-linked and criminal hackers use device code phishing against M365 users

ID: 41a16aee-0af1-563f-8974-c67e9a2682b2

STIX ID: report--41a16aee-0af1-563f-8974-c67e9a2682b2

Feed Name: Proofpoint Blog

Threat Score
70/100

Date Published: 2025-12-19

Date Updated: 2026-04-28

...
...

Multiple China- and Russia-linked APTs and criminal groups have conducted active device code phishing campaigns that trick users into authorizing Microsoft 365 access via legitimate device authorization flows; attackers use tools like SquarePhish2 and the Graphish phishing kit (and sellable tools from an actor tracked as TA2723) to harvest tokens and take over M365 accounts, targeting governments, think tanks, higher education, transportation and other organizations in the U.S. and Europe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.