Dynamic Device Code Phishing
ID: 2c823159-da27-5eba-8f83-b341c49b7829
STIX ID: report--2c823159-da27-5eba-8f83-b341c49b7829
Feed Name: Black Hills Infosec Blog
The report describes a dynamic device code phishing technique targeting Microsoft and Azure environments, explaining how attackers generate device codes via an Azure-hosted landing page and capture server to obtain access and refresh tokens, then leverage tools like TokenTactics to pivot tokens across audiences (e.g., Outlook, MS Graph). It outlines the attack flow, operational setup at a high level (including the use of CORS-Anywhere and Azure Web Apps), notes detection artifacts such as source IP tied to code generation and MFA implications, and recommends defensive measures like Conditional Access and sign-in protections to detect or block token abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
