Microsoft 365 Tokens Stolen Through OAuth Device Authorization Attacks
ID: 4b839fc7-5148-58b8-8ba8-4414de24f793
STIX ID: report--4b839fc7-5148-58b8-8ba8-4414de24f793
Feed Name: Cyber Press
Threat Score
This report describes an active, large-scale shift to OAuth device code phishing where attackers use PhaaS kits (e.g., EvilTokens, ODx) and AI-generated landing pages to trick Microsoft 365 users into authorizing device codes, allowing immediate token theft and account takeover that can lead to email hijacking and ransomware; the report details TTPs, mitigation recommendations (block or restrict device code flows via Conditional Access), and provides sample IOCs for hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
