OAuth Device Code Phishing: A New Microsoft 365 Account Breach Vector
ID: 02cd77fc-31ea-519c-8897-4173248790da
STIX ID: report--02cd77fc-31ea-519c-8897-4173248790da
Feed Name: ANY.RUN's Cybersecurity Blog
ANY.RUN reports a rapidly growing phishing campaign that exploits Microsoft’s OAuth Device Code flow to obtain access and refresh tokens—allowing account takeover of Microsoft 365 tenants without credential theft. The analysis explains the attacker-initiated device authorization workflow, provides multiple worker[.]dev IOCs and decrypted network artifacts, and recommends SOC improvements (SSL decryption, behavioral detection, TI feeds and sandboxing) to detect and remediate this token-based compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
