Hackers Using Phishing Tools to Access M365 Accounts via OAuth Device Code
ID: b717d9ae-2518-516f-9cfd-09b8ef0a3056
STIX ID: report--b717d9ae-2518-516f-9cfd-09b8ef0a3056
Feed Name: cybersecurityNews.com
Threat actors are conducting large-scale OAuth device code phishing campaigns against Microsoft 365 users: victims are lured to fake pages that display device codes and instructed to enter them on Microsoft’s real devicelogin portal, allowing attacker-controlled apps to poll for and receive access tokens. Researchers observed two tooling families (SquarePhish2 and Graphish) and multiple adversaries including financially motivated and state-aligned groups; mitigations include blocking or restricting device code flows via Conditional Access and improving user training about device codes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
