Tag

Device Code Phishing

All articles tagged with #device code phishing

SVR weaponizes public Wi‑Fi to deploy malware and harvest credentials
technology21 days ago

SVR weaponizes public Wi‑Fi to deploy malware and harvest credentials

Microsoft disclosed that Russian SVR operatives are compromising captive-portal public Wi‑Fi networks at hotels and conference venues to deliver malware (CornFlake) and in-memory tools (ChocoShell) through a CaptiveCrunch campaign, using adversary‑in‑the‑middle traffic manipulation, fake update prompts, and device‑code phishing to steal credentials and access cloud accounts. The guidance emphasizes avoiding public networks, using personal hotspots, and enabling passwordless authentication while organizations should disable device‑code flows where possible.

Device Code Phishing Surges in 2026, Defeating MFA Across Platforms
security23 days ago

Device Code Phishing Surges in 2026, Defeating MFA Across Platforms

Device code phishing, using OAuth 2.0 device flows, has become an industrial-scale threat in 2026, enabling token theft that defeats MFA across providers via a thriving phishing-as-a-service ecosystem with 25+ kits. Attackers shift from authentication to authorization abuse, driven by AI-assisted kit development, and detection must occur at the browser during the device-code approval, since network defenses can’t block these attacks.

Phishers roll out two new kits to target Microsoft 365, sidestep MFA
technology1 month ago

Phishers roll out two new kits to target Microsoft 365, sidestep MFA

Two new phishing toolkits, Jalisco and OmegaLord, target Microsoft 365 accounts and bypass MFA: Jalisco uses OAuth device-code phishing to trick victims into authorizing attacker-controlled devices and can auto-generate fresh device codes to defeat the 15-minute window, while OmegaLord masquerades as a PDF reader to steal credentials and phone numbers to aid MFA interception. Attacks can lead to rapid data exfiltration from SharePoint and other SaaS apps, sometimes within minutes, prompting researchers to urge tighter controls: reduce Entra ID device-registration limits from 50 to 1-2, block device-code authentication via Entra Conditional Access, restrict OAuth Device Authorization grants in Okta, and audit/remove unnecessary app registrations.

ARToken: A New PhaaS Armoring EvilTokens’ Microsoft 365 Toolkit
security1 month ago

ARToken: A New PhaaS Armoring EvilTokens’ Microsoft 365 Toolkit

Cisco Talos flags ARToken as a new phishing-as-a-service platform allied with EvilTokens, offering a wide toolkit to steal Microsoft 365 tokens, maintain persistence with Primary Refresh Tokens, and access Outlook, SharePoint, and OneDrive. It uses Cloudflare Workers for deployment, supports multi-tenant campaigns, and includes inbox rules, keyword monitoring, and data exfiltration tools. The kit mirrors EvilTokens’ device-code phishing flow to bypass MFA, with research suggesting a shared ecosystem and AI-enabled workflows that automate BEC-style fraud. Security teams should prioritize behavioral AI defenses and robust email security controls.

Tycoon2FA Expands to Device-Code Phishing Targeting Microsoft 365
security3 months ago

Tycoon2FA Expands to Device-Code Phishing Targeting Microsoft 365

A new Tycoon2FA variant uses device-code phishing via a Trustifi click-tracking URL to hijack Microsoft 365 accounts by steering victims to the legitimate device-login flow at microsoft.com/devicelogin, granting attackers OAuth tokens and access to email, calendar, and files. After a takedown, the kit resurfaced with obfuscation and new delivery chains, prompting defenders to disable the device-code flow when not needed, restrict OAuth permissions, enable Continuous Access Evaluation, and monitor Entra logs for deviceCode activity and related IoCs.