Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow
ID: dae66982-3c23-59d7-bc35-bbdd9caeca0e
STIX ID: report--dae66982-3c23-59d7-bc35-bbdd9caeca0e
Feed Name: cybersecurityNews.com
This report enumerates dozens of URLs identified as phishing kit landing pages that leverage Microsoft device-code and Live authentication endpoints (e.g., login.microsoftonline.com, aka.ms/devicelogin) to phish credentials; it additionally lists a YARA rule (DeviceCode_Phishing_LandingPageHTML) used to detect these landing pages. The collection indicates an active phishing campaign abusing legitimate auth flows to harvest credentials and provides IOC data for detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
