logo

Inside an AI‑enabled device code phishing campaign

ID: 6fd15219-63c2-5f59-9aed-40e2143d470f

STIX ID: report--6fd15219-63c2-5f59-9aed-40e2143d470f

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender observed a large-scale, automated device-code phishing campaign (EvilToken Phishing-as-a-Service) that uses cloud PaaS, dynamic device code generation at click-time, clipboard manipulation, and backend polling to bypass the 15-minute device-code window and MFA, resulting in access-token theft, targeted reconnaissance via Microsoft Graph, device registration for persistence, and email exfiltration; the report provides IOCs, advanced hunting queries, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.