logo

State-linked and criminal hackers use device code phishing against M365 users

ID: 5095708c-e66b-59dc-946b-b58be815955d

STIX ID: report--5095708c-e66b-59dc-946b-b58be815955d

Feed Name: Proofpoint Blog

Threat Score
75/100

Date Published: 2025-12-19

Date Updated: 2026-04-28

...
...

Multiple nation-state and criminal groups are running device code phishing campaigns that trick users into entering Microsoft device authorization codes to grant attackers access to Microsoft 365 accounts; campaigns leverage kits such as SquarePhish2 and Graphish and have targeted governments, think tanks, higher education and transportation organizations in the US and Europe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.