logo

OAuth Device Code Phishing Campaigns Surge Targets Microsoft 365

ID: 3cc869f7-48df-58b0-980e-d0e6079db6a7

STIX ID: report--3cc869f7-48df-58b0-980e-d0e6079db6a7

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2025-12-18

Date Updated: 2026-04-22

...
...

**Executive Summary:** A surge of phishing campaigns is exploiting Microsoft’s OAuth device code authorization flow to trick users into approving malicious applications and grant attackers access tokens for Microsoft 365 account takeover; campaigns use QR codes, embedded buttons/links and phishing kits (SquarePhish2, Graphish) and include financially motivated actors (TA2723) and Russia-aligned groups (UNK_AcademicFlare) targeting government, academic, transportation and other sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.