logo

Microsoft 365 Users Targeted by Device Code Phishing Campaign Using OAuth 2.0 Flow

ID: 9d064f9f-f626-5b9b-b6e2-e7d61fb8153a

STIX ID: report--9d064f9f-f626-5b9b-b6e2-e7d61fb8153a

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Varshini

...
...

Active phishing campaign targeting Microsoft 365 users leverages the OAuth 2.0 Device Authorization (device code) flow to convince victims to authorize attacker-controlled devices, enabling account takeover without stealing passwords. The kit uses evasion (invisible Unicode characters, encoded/bit-shifted device-code artifacts), generates distinctive network beaconing behavior, and includes IOCs and YARA/network detection guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.