The Device Code Phishing Tsunami: What We’re Seeing in the Wild
ID: 8b825aaa-c0c6-5a98-b1e2-b1dcf8b7598a
STIX ID: report--8b825aaa-c0c6-5a98-b1e2-b1dcf8b7598a
Feed Name: LevelBlue SpiderLabs Blog
Device-code flow phishing targeting Microsoft 365 has surged into a commoditized, large-scale threat: multiple PhaaS kits (EvilTokens, Kali365, Ghost Hub, Cyb3r, Tycoon2FA) are operationalizing the technique with sophisticated evasion (passworded PDFs, multi-stage redirectors, abuse of trusted platforms, CAPTCHA/antibot, QR/SVG attachments) to harvest OAuth tokens for mailbox access and BEC; defenders are advised to restrict or disable device code flow, monitor sign-ins, and strengthen Conditional Access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
