Microsoft 365 Under Siege: Phishing Campaign Bypasses MFA Across 5 Countries
ID: b18dfd9f-34c0-508a-961c-c6812117c513
STIX ID: report--b18dfd9f-34c0-508a-961c-c6812117c513
Feed Name: TechRepublic Security
Huntress identified a widespread phishing campaign impacting over 340 organizations across the US, Canada, Australia, New Zealand, and Germany that leverages Microsoft’s OAuth device code flow to harvest access tokens (bypassing MFA). Attack infrastructure is hosted on Railway.com (notably CIDR blocks 162.220.232.0/22 and 162.220.234.0/22 and specific IPs 162.220.234.41, 162.220.234.66, 162.220.232.57), and the operation is tied to a phishing-as-a-service called EvilTokens; Huntress mitigated active abuse by pushing conditional access blocks and recommends revoking tokens, blocking Railway IP ranges, disabling device code auth if unused, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
