AI-enabled device code phishing campaign exploits OAuth flow for account takeover
ID: dec23795-d300-5183-89d7-bb501439de32
STIX ID: report--dec23795-d300-5183-89d7-bb501439de32
Feed Name: Help Net Security
Microsoft Defender observed a sophisticated phishing campaign that automates generation and delivery of OAuth device codes to trick users into authorizing attacker sessions — effectively bypassing MFA. The attackers use browser-in-the-browser interfaces, compromised legitimate domains and serverless platforms, and background scripts that poll authentication status; post-compromise activity includes device registration for Primary Refresh Tokens (PRTs), mailbox rule creation, Microsoft Graph reconnaissance, and selective data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
