Hackers Abuse OAuth Device Codes and Entra ID Enrollment for Persistent SaaS Access
ID: e000b2be-9ea4-594b-8790-8cc47d1fb5a4
STIX ID: report--e000b2be-9ea4-594b-8790-8cc47d1fb5a4
Feed Name: GBHackers
This report describes evolving AI-enabled phishing-as-a-service campaigns (notably Jalisco and OmegaLord) that generate OAuth device codes in real time and abuse Microsoft Entra ID device enrollment to capture access/refresh tokens and acquire Primary Refresh Tokens (PRTs), enabling MFA bypass and durable persistence across password resets. The toolkits enable scalable credential- and token-theft, rapid data exfiltration, and enrollment of malicious devices; the report includes IOCs, examples, and actionable mitigations such as disabling device code flow where unused, auditing application and device registrations, revoking sessions, and monitoring anomalous token and device activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
