logo

Hackers Exploit OAuth Device Flow to Steal Microsoft 365 Tokens

ID: 377e47c5-79fc-5f7d-8eee-01ec2f42c389

STIX ID: report--377e47c5-79fc-5f7d-8eee-01ec2f42c389

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Mayura Kathir

...
...

This report details a rapid increase in device code phishing—where attackers trick users into authorizing malicious applications via Microsoft’s OAuth device flow—driven by criminal toolkits (EvilTokens, ODx, Kali365) and phishing-as-a-service offerings; it highlights TA4903’s campaigns, dynamic on-demand code generation, numerous phishing domains/landing pages as IOCs, the potential for enterprise account takeovers and follow-on ransomware or fraud, and recommends mitigations such as restricting device code flows via conditional access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.