Microsoft 365 accounts targeted in wave of OAuth phishing attacks
ID: d1b84b3e-5a49-5d72-9217-dd90398ab6c0
STIX ID: report--d1b84b3e-5a49-5d72-9217-dd90398ab6c0
Feed Name: Bleeping Computer
Proofpoint reports a surge in OAuth device code phishing targeting Microsoft 365 accounts where attackers trick users into entering device codes on Microsoft's legitimate device login page to authorize attacker-controlled applications. Campaigns use phishing kits (SquarePhish v1/v2 and Graphish) and lures like document-sharing or token reauthorization; actors include financially motivated groups (TA2723) and a suspected Russia-aligned actor (UNK_AcademicFlare). Proofpoint recommends mitigations such as Microsoft Entra Conditional Access and sign-in origin policies to reduce successful account takeovers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
