logo

Beware of Device Code Phishing

ID: c1143e5c-da75-5b69-9b85-bf7e3f2fb0dd

STIX ID: report--c1143e5c-da75-5b69-9b85-bf7e3f2fb0dd

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-06-04

Date Updated: 2026-04-21

Author: Stu Sjouwerman

...
...

The report explains device code phishing — an OAuth-based social engineering technique in which attackers induce victims to enter a device code on a legitimate authentication page, enabling attackers to harvest access and refresh tokens that bypass MFA and conditional access. It cites real-world use by APT29 and the Storm-2372 campaign against Microsoft Entra ID and collaboration platforms, outlines why the technique is effective (no malicious links/attachments, leverages user habits), and provides mitigations including user training, conditional access enforcement, OAuth activity monitoring, least-privilege OAuth scopes, and token revocation practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.