logo

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

ID: 7209f7e1-cd69-509e-a0cb-d106deb7165b

STIX ID: report--7209f7e1-cd69-509e-a0cb-d106deb7165b

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-07

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

A Microsoft 365 device-code phishing campaign observed between late June and early July 2026 uses collaboration- and Teams-style lures to trick users into entering attacker-provided device codes, allowing adversaries to capture OAuth device tokens and take over accounts; the operations leverage reusable PhaaS tooling (DEBULL) and share tradecraft and infrastructure with known platforms such as EvilTokens, ARToken, and Tycoon, enabling post-compromise actions (email/file exfiltration, BEC, persistence) via GraphSpy-derived workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.