Hackers Abuse Microsoft OAuth Device Code Flow to Take Over Microsoft 365 Accounts
ID: 1de742d3-e5e9-5c5d-8f9a-895a3b05491c
STIX ID: report--1de742d3-e5e9-5c5d-8f9a-895a3b05491c
Feed Name: GBHackers
**Device-code phishing campaign targeting Microsoft 365:** An active phishing campaign lures users to a realistic landing page that triggers Microsoft’s legitimate device login flow (aka.ms/devicelogin). Victims are tricked into entering a displayed device code, which the attacker’s backend redeems to obtain OAuth tokens and full access to Microsoft 365 accounts without passwords. The kit uses defense-evasion techniques (invisible Unicode characters, algorithmic attachment IDs, a bit-shifted Entra ID artifact) and produces a distinctive three-phase network pattern and four-second beaconing that support YARA and network detections; defenders are advised to monitor for these artifacts and enforce conditional access and MFA controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
