Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA
ID: 43b73db9-5941-55ce-ade7-153feab0a8fb
STIX ID: report--43b73db9-5941-55ce-ade7-153feab0a8fb
Feed Name: KnowBe4 Blog
KnowBe4 Threat Labs observed an active North America-focused phishing campaign (first seen December 2025) that tricks victims into entering attacker-supplied device codes at the legitimate Microsoft device login portal, enabling real-time theft of OAuth access and refresh tokens and effectively bypassing passwords and MFA. The report outlines a five-phase attack flow, examples of social-engineering lures, IOCs (malicious senders, domains, cloud storage URLs, subject patterns), and immediate/strategic mitigations including blocking IOCs, auditing OAuth app consent, reviewing Azure AD sign-in logs, and disabling the device code flow via Conditional Access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
