logo

Device Code Phishing in Google Cloud and Azure | Huntress

ID: b9f8db9d-4a8a-5cf3-878b-1c2f997e890b

STIX ID: report--b9f8db9d-4a8a-5cf3-878b-1c2f997e890b

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2025-02-06

Date Updated: 2026-04-28

...
...

This post analyzes the OAuth 2.0 device authorization (device code) flow and demonstrates how attackers can phish victims to obtain access and refresh tokens by requesting device codes, tricking users into authenticating, and polling token endpoints; it finds Microsoft Azure's implementation allows powerful token scopes (enabling severe tenant compromise in some cases) while Google limits supported scopes, substantially reducing the attack's impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.