logo

Hundreds of orgs compromised daily in Microsoft device code phishing attacks

ID: 02a99fb0-8ce1-53c0-9e5e-857d83da853e

STIX ID: report--02a99fb0-8ce1-53c0-9e5e-857d83da853e

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft researchers observed a high-volume device-code phishing campaign (linked to the EvilTokens kit) launching multiple distinct waves daily that use AI-personalized phishing, dynamic OAuth device codes generated at the final redirect stage, and automated redirect chains through legitimate serverless platforms to evade detection, bypass MFA, and steal Microsoft 365 access tokens; post-compromise activity repeatedly targets finance-related inboxes for automated email exfiltration and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.