logo

Go With the Flow: Abusing OAuth Device Code Flow

ID: ff46e72f-35ca-559c-8075-f23ed752da9d

STIX ID: report--ff46e72f-35ca-559c-8075-f23ed752da9d

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
72/100

Date Published: 2026-04-20

Date Updated: 2026-04-28

Author: Jakub Wiewiorski

...
...

LevelBlue GTO analyzed a phishing campaign that leverages Microsoft’s OAuth 2.0 Device Code Flow: a malicious site dynamically requests a device_code from Microsoft, displays the user_code to victims via a fake Adobe page, and polls for token issuance—resulting in account compromise and persistent access (refresh tokens). The report details the JavaScript workflow, compromised redirect infrastructure, detection KQL queries, recommended mitigations (block the Device Code Flow via Conditional Access), and provides an observed IOC (https://adobe.safest.org/).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.