logo

The Device Code Phishing Tsunami: What We’re Seeing in the Wild

ID: 8b825aaa-c0c6-5a98-b1e2-b1dcf8b7598a

STIX ID: report--8b825aaa-c0c6-5a98-b1e2-b1dcf8b7598a

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-06-10

Author: John Kevin Adriano

...
...

Device-code flow phishing targeting Microsoft 365 has surged into a commoditized, large-scale threat: multiple PhaaS kits (EvilTokens, Kali365, Ghost Hub, Cyb3r, Tycoon2FA) are operationalizing the technique with sophisticated evasion (passworded PDFs, multi-stage redirectors, abuse of trusted platforms, CAPTCHA/antibot, QR/SVG attachments) to harvest OAuth tokens for mailbox access and BEC; defenders are advised to restrict or disable device code flow, monitor sign-ins, and strengthen Conditional Access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.