Go With the Flow: Abusing OAuth Device Code Flow
ID: ff46e72f-35ca-559c-8075-f23ed752da9d
STIX ID: report--ff46e72f-35ca-559c-8075-f23ed752da9d
Feed Name: LevelBlue SpiderLabs Blog
LevelBlue GTO analyzed a phishing campaign that leverages Microsoft’s OAuth 2.0 Device Code Flow: a malicious site dynamically requests a device_code from Microsoft, displays the user_code to victims via a fake Adobe page, and polls for token issuance—resulting in account compromise and persistent access (refresh tokens). The report details the JavaScript workflow, compromised redirect infrastructure, detection KQL queries, recommended mitigations (block the Device Code Flow via Conditional Access), and provides an observed IOC (https://adobe.safest.org/).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
