logo

Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow

ID: dae66982-3c23-59d7-bc35-bbdd9caeca0e

STIX ID: report--dae66982-3c23-59d7-bc35-bbdd9caeca0e

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Tushar Subhra Dutta

...
...

This report enumerates dozens of URLs identified as phishing kit landing pages that leverage Microsoft device-code and Live authentication endpoints (e.g., login.microsoftonline.com, aka.ms/devicelogin) to phish credentials; it additionally lists a YARA rule (DeviceCode_Phishing_LandingPageHTML) used to detect these landing pages. The collection indicates an active phishing campaign abusing legitimate auth flows to harvest credentials and provides IOC data for detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.