DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
ID: 7209f7e1-cd69-509e-a0cb-d106deb7165b
STIX ID: report--7209f7e1-cd69-509e-a0cb-d106deb7165b
Feed Name: The Hacker News
A Microsoft 365 device-code phishing campaign observed between late June and early July 2026 uses collaboration- and Teams-style lures to trick users into entering attacker-provided device codes, allowing adversaries to capture OAuth device tokens and take over accounts; the operations leverage reusable PhaaS tooling (DEBULL) and share tradecraft and infrastructure with known platforms such as EvilTokens, ARToken, and Tycoon, enabling post-compromise actions (email/file exfiltration, BEC, persistence) via GraphSpy-derived workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
