GraphSpy in the Wild: Exposed Device Code Phishing Operation
ID: 299fc44e-38d9-50af-92e1-5db9e9e0871e
STIX ID: report--299fc44e-38d9-50af-92e1-5db9e9e0871e
Feed Name: On the Hunt
An exposed admin panel for a GraphSpy-based device-code phishing tool was discovered, revealing real victim OAuth tokens and a custom Python wrapper that generated XOR-obfuscated phish pages, managed ephemeral Cloudflare Quick Tunnels, and provided C2 endpoints for device-code capture. The deployment successfully captured tokens from 24 victims and can perform Azure AD device joins to obtain Primary Refresh Tokens (PRTs), enabling persistent Microsoft 365 access; the report includes IOCs, network indicators, and actionable detection queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
