logo

AI-enabled device code phishing campaign exploits OAuth flow for account takeover

ID: dec23795-d300-5183-89d7-bb501439de32

STIX ID: report--dec23795-d300-5183-89d7-bb501439de32

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-28

Author: Anamarija Pogorelec

...
...

Microsoft Defender observed a sophisticated phishing campaign that automates generation and delivery of OAuth device codes to trick users into authorizing attacker sessions — effectively bypassing MFA. The attackers use browser-in-the-browser interfaces, compromised legitimate domains and serverless platforms, and background scripts that poll authentication status; post-compromise activity includes device registration for Primary Refresh Tokens (PRTs), mailbox rule creation, Microsoft Graph reconnaissance, and selective data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.