logo

Uncovering a New Device Code Phishing Campaign

ID: 56c7a481-e008-55a1-9f55-82a8fbf15c32

STIX ID: report--56c7a481-e008-55a1-9f55-82a8fbf15c32

Feed Name: On the Hunt

Threat Score
70/100

Date Published: 2026-03-10

Date Updated: 2026-04-19

Author: Paul Newton

...
...

This report describes a phishing campaign that abuses Microsoft device code authentication by hosting Adobe-themed lures on Cloudflare workers.dev domains; attackers auto-copy device codes and direct victims to Microsoft’s device login to capture OAuth tokens. The document provides code analysis, a list of observed workers.dev phishing domains and inferred sender addresses, Log Analytics detection queries, and recommended detection hunts to surface device-code-based compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.