Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
ID: 52c1f16b-5230-5277-a189-9ad9f9a53603
STIX ID: report--52c1f16b-5230-5277-a189-9ad9f9a53603
Feed Name: The Hacker News
Threat Score
Cybersecurity vendors report an active device-code phishing campaign that leverages Cloudflare Workers and Railway-hosted infrastructure to harvest Microsoft 365 OAuth tokens from victims across more than 340 organizations in multiple countries; attackers use multi-hop redirects, landing-page code generation, anti-analysis controls, and a phishing-as-a-service (EvilTokens) to bypass filters and persist access (tokens remain valid despite password resets).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
