logo

Device code phishing attacks surge 37x as new kits spread online

ID: d1c5f5e5-1ff0-53fe-868d-8e8dd5880719

STIX ID: report--d1c5f5e5-1ff0-53fe-868d-8e8dd5880719

Feed Name: Bleeping Computer

Threat Score
74/100

Date Published: 2026-04-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Device code phishing abuses the OAuth 2.0 Device Authorization Grant to trick victims into authorizing attacker-controlled devices; Push Security and Sekoia report a ~37.5x rise in these attacks in 2026 driven by phishing-as-a-service kits (notably EvilTokens) and numerous competing kits that use realistic SaaS lures, anti-bot measures, and cloud hosting. The write-up lists at least 11 kits and provides mitigation recommendations such as disabling the device-code flow when unnecessary, enforcing conditional access, and monitoring for anomalous device-code authentication events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.