logo

OAuth Device Code Phishing: A New Microsoft 365 Account Breach Vector

ID: 02cd77fc-31ea-519c-8897-4173248790da

STIX ID: report--02cd77fc-31ea-519c-8897-4173248790da

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
75/100

Date Published: 2026-03-10

Date Updated: 2026-04-26

Author: ANY.RUN

...
...

ANY.RUN reports a rapidly growing phishing campaign that exploits Microsoft’s OAuth Device Code flow to obtain access and refresh tokens—allowing account takeover of Microsoft 365 tenants without credential theft. The analysis explains the attacker-initiated device authorization workflow, provides multiple worker[.]dev IOCs and decrypted network artifacts, and recommends SOC improvements (SSL decryption, behavioral detection, TI feeds and sandboxing) to detect and remediate this token-based compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.