Inside an AI‑enabled device code phishing campaign
ID: 6fd15219-63c2-5f59-9aed-40e2143d470f
STIX ID: report--6fd15219-63c2-5f59-9aed-40e2143d470f
Feed Name: Microsoft Security
Date Published: 2026-04-06
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
Microsoft Defender observed a large-scale, automated device-code phishing campaign (EvilToken Phishing-as-a-Service) that uses cloud PaaS, dynamic device code generation at click-time, clipboard manipulation, and backend polling to bypass the 15-minute device-code window and MFA, resulting in access-token theft, targeted reconnaissance via Microsoft Graph, device registration for persistence, and email exfiltration; the report provides IOCs, advanced hunting queries, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
