Skip to content
September 15, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • Device Code Phishing: Microsoft 365 Attack That Steals No Passwords
  • Cybercriminals

Device Code Phishing: Microsoft 365 Attack That Steals No Passwords

Do Son June 20, 2026 3 minutes read
0
Head Mare TrueConf attack PhantomCore backdoor diagram
Add Daily CyberSecurity as a preferred source on Google

A clever new phishing technique skips the password entirely. ReversingLabs has uncovered an active device code phishing campaign that hijacks Microsoft 365 accounts. Instead of faking a login page, the attackers abuse a real Microsoft sign-in flow. As the researchers put it, the kit “abuses Microsoft’s legitimate OAuth 2.0 Device Authorization Grant flow.”

No Password Required

This is what makes the attack so dangerous. “Rather than stealing passwords through a counterfeit login page,” the kit takes a different route. It “persuades victims to complete a legitimate Microsoft authentication process that authorizes an attacker-controlled device.” In short, the victim hands over access without ever leaking a password.

Because the login happens on real Microsoft pages, classic warning signs vanish. There is no fake domain to spot. No suspicious certificate raises a flag either. Consequently, even careful users can fall for it.

A Technique on the Rise

Device code phishing is not entirely new. The OAuth 2.0 device flow normally helps smart TVs and command-line tools log in. However, attackers have learned to twist it for account theft. Over the past year, both criminal and state-aligned groups have embraced the tactic. Phishing-as-a-service kits have lowered the bar even further. This RL campaign shows how polished those operations have become.

How the Attack Unfolds

The lure arrives as a business email. It poses as a vendor estimate awaiting approval. Notably, the message hides its image behind a clickable HTML attachment. One click sends the victim to a polished, ClickFix-style landing page.

There, a “Review Document” button reveals a verification code. The page then tells the victim to copy that code and sign in with Microsoft. Crucially, the sign-in popup is genuine. It lives on Microsoft’s own aka.ms/devicelogin entry point.

When the victim enters the code, they unknowingly approve the attacker’s device. From that moment, the criminal holds a valid token for the Microsoft 365 account. A later Microsoft prompt even names the “Microsoft Authentication Broker” and “another device” a subtle clue something is wrong. As a result, the account takeover completes silently.

Device code phishing flow abusing Microsoft 365 OAuth device authorization for account takeover
Microsoft Authentication Broker username prompt | Image:

Built to Dodge Detection

The phishing kit also works hard to stay hidden. For instance, it sprinkles invisible Unicode characters through its code. These zero-width spaces split red-flag words like “Verify” and “Microsoft.” Therefore, simple string-matching scanners miss them.

Behind the scenes, the kit beacons constantly. It sends the device code to its server every four seconds. This loop keeps the attacker’s OAuth flow in sync with the victim. The kit also routes through Akamai-hosted Microsoft URLs, which boosts its air of legitimacy.

How to Spot Device Code Phishing

Detection is still possible, however. RL notes that “the Microsoft authentication alone is not malicious.” Yet pairing that login with four-second beaconing exposes the scheme. So network defenders should hunt for that telltale traffic pattern. Security teams can also watch for the specific hostname-resolution sequences RL documented.

For users, the rule is simple. Treat any unsolicited code you are told to enter at a Microsoft prompt as suspicious. Microsoft’s own dialog even warns, “Do not enter codes from sources you don’t trust.” User training that focuses only on URLs will not catch this.

Device code phishing represents a growing threat, and it will not be the last campaign of its kind. Above all, organizations should review Entra ID sign-in logs for unexpected device code grants.

Related coverage

  • The “Graphalgo” Evolution: How North Korea Built a Fake Florida LLC to Hack Developers
  • Fire Ant Threat Actor Targets Trusted Infrastructure
  • UAC-0057 Targets Ukraine and Poland with Weaponized Archives and Evolving Implants
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover Device Authorization Grant Device Code Phishing Microsoft 365 OAuth phishing ReversingLabs

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-91949CVSS 9.3
    FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that...
  • CVE-2026-63696CVSS 9.1
    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of...
  • CVE-2026-63695CVSS 9.8
    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation...
  • CVE-2026-39919CVSS 9.8
    Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG...
  • CVE-2026-91998CVSS 9.9
    Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint...
  • CVE-2026-91995CVSS 9.1
    pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint...
  • CVE-2026-90711CVSS 9.1
    proxy-addr is a Node.js module that determines a request's client address behind...
  • CVE-2026-91003CVSS 9.1
    A flaw has been found in D-Link DI-8300 16.07. The affected element...
  • CVE-2026-91001CVSS 9.9
    A security flaw has been discovered in D-Link DI-8400 16.07. This affects...
  • CVE-2026-90847CVSS 9.1
    A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.