New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow
ID: 1ab395b4-f9fb-5712-8049-db7be5908894
STIX ID: report--1ab395b4-f9fb-5712-8049-db7be5908894
Feed Name: securityonline.info
Microsoft Defender Security Research details a large-scale phishing campaign that abuses the Device Code Authentication flow to hijack organizational accounts. Attackers used a PhaaS toolkit (EvilToken) with dynamic device-code generation, clipboard hijacking, automated polling, AI-personalized lures, and serverless hosting to evade detection; once inside, they performed Microsoft Graph reconnaissance and created mailbox rules to exfiltrate value (e.g., wire transfer details) and maintain persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
