logo

GraphSpy in the Wild: Exposed Device Code Phishing Operation

ID: 299fc44e-38d9-50af-92e1-5db9e9e0871e

STIX ID: report--299fc44e-38d9-50af-92e1-5db9e9e0871e

Feed Name: On the Hunt

Threat Score
70/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Paul Newton

...
...

An exposed admin panel for a GraphSpy-based device-code phishing tool was discovered, revealing real victim OAuth tokens and a custom Python wrapper that generated XOR-obfuscated phish pages, managed ephemeral Cloudflare Quick Tunnels, and provided C2 endpoints for device-code capture. The deployment successfully captured tokens from 24 victims and can perform Azure AD device joins to obtain Primary Refresh Tokens (PRTs), enabling persistent Microsoft 365 access; the report includes IOCs, network indicators, and actionable detection queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.