logo

Microsoft 365 Tokens Stolen Through OAuth Device Authorization Attacks

ID: 4b839fc7-5148-58b8-8ba8-4414de24f793

STIX ID: report--4b839fc7-5148-58b8-8ba8-4414de24f793

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: Varshini

...
...

This report describes an active, large-scale shift to OAuth device code phishing where attackers use PhaaS kits (e.g., EvilTokens, ODx) and AI-generated landing pages to trick Microsoft 365 users into authorizing device codes, allowing immediate token theft and account takeover that can lead to email hijacking and ransomware; the report details TTPs, mitigation recommendations (block or restrict device code flows via Conditional Access), and provides sample IOCs for hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.