Hackers Exploit OAuth Device Flow to Steal Microsoft 365 Tokens
ID: 377e47c5-79fc-5f7d-8eee-01ec2f42c389
STIX ID: report--377e47c5-79fc-5f7d-8eee-01ec2f42c389
Feed Name: GBHackers
This report details a rapid increase in device code phishing—where attackers trick users into authorizing malicious applications via Microsoft’s OAuth device flow—driven by criminal toolkits (EvilTokens, ODx, Kali365) and phishing-as-a-service offerings; it highlights TA4903’s campaigns, dynamic on-demand code generation, numerous phishing domains/landing pages as IOCs, the potential for enterprise account takeovers and follow-on ransomware or fraud, and recommends mitigations such as restricting device code flows via conditional access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
