Redirect to legitimate device code sign-in page
At a glance
- Actor or group: Unidentified cybercrime group (financially motivated threat actors)
- Activity type: Device code phishing, OAuth token theft, and business email compromise
- Targets or victims: Enterprise sales teams and service providers across North America
- Scale: Over 30 lookalike domains targeting wholesale distributors and manufacturers
- Jurisdiction or law-enforcement status: Active threat under ongoing private intelligence monitoring
- Source: eSentire Threat Response Unit (TRU)
TL;DR
Security researchers uncovered a new GhostCode phishing kit that abuses Microsoft authentication workflows. Attackers trick corporate employees into authorizing device codes through password-protected attachments and fake non-disclosure agreements. Once authorized, threat actors acquire persistent administrative tokens and compromise internal company communications.
What Happened
The intrusion begins through legitimate web contact forms on corporate websites. Attackers submit an inquiry while posing as procurement executives from well-known retail enterprises. After sales representatives follow up, the threat actors promise to share project specifications under an agreement.
The attackers then email a file transfer link hosting a password-protected HTML attachment. When opened in a web browser, the file displays a fake document portal named FlipBook. The file contains three distinct evasion techniques. First, the developers inject thousands of junk characters to bloat the file size. This padding disrupts file scanning engines and alters file similarity hashes.

Second, the authors inject comments between every visible character in the markup. This tactic scrambles the raw code while displaying clean text on the screen. Third, the redirect address remains encrypted using AES-256-GCM. The browser decrypts the target address only after the victim inputs the password.
Next, the victim passes through an anti-bot verification challenge. The server then directs the visitor to a fraudulent portal. Behind the scenes, the attacker connects to Microsoft servers to request an authorization code. As eSentire noted, “Device code phishing kits abuse the OAuth 2.0 device authorization grant flow to gain access to Microsoft accounts.”
The portal displays this code and directs the victim to Microsoft’s official device login page. Trusting the brand, the user enters the code and completes multi-factor authentication. Immediately afterward, the phishing server captures the generated session tokens. To avoid suspicion, the platform presents a fake non-disclosure agreement on corporate letterhead.
Who Is Behind It
Researchers attribute this activity to an unidentified cybercrime cluster with moderate confidence. The operational team named the tooling based on specific network traits. TRU stated: “The name reflects two characteristics observed during analysis.” The team explained that “Ghost” denotes network activity and “Code” marks device code abuse.
The suspects demonstrate disciplined operational habits. They use commercial proxy networks to route traffic through internet connections in the victim’s country. Consequently, the Microsoft login portal displays a matching regional location to the victim. Furthermore, the operators register disposable domains using privacy-focused email accounts. They also direct incoming communications through established cloud mail services.
Impact or Scale
The operational speed of the GhostCode phishing kit creates severe organizational exposure. Within five seconds of authentication, attackers start issuing automated administrative requests. In one analyzed incident, the intruders registered three distinct rogue devices in seventy-eight seconds.
Just thirty-two seconds after login, the operators acquired a Primary Refresh Token. This credential enables single sign-on access across the entire Microsoft 365 tenant. With this token, the attackers bypassed device compliance rules and enrolled hardware into device management systems.
The threat actors then harvested internal email messages and business records. Analysts identified more than thirty lookalike domains registered during August 2026 alone. These domains impersonated distribution networks, food suppliers, and warehousing firms. This infrastructure indicates a broad campaign against commercial vendors.
Protection and Future Outlook
Cybercriminals will continue targeting alternative identity protocols as organizations adopt multi-factor authentication. Because device authorization grants require no credential cloning, attackers will likely expand these operations. Organizations must restrict the OAuth device code flow across corporate tenants.
Security teams should block device code authentication for standard desktop users. Administrators can enforce conditional access policies that limit authentication to compliant, corporate-managed devices. Furthermore, companies should inspect directory logs for rapid device registrations. Security operation centers should alert on device names with incrementing numerical suffixes.
Finally, organizations must train customer-facing staff on contact form deception. Sales representatives should verify business identities before opening external file links. By combining strong identity policies with user awareness, enterprises can neutralize these attacks.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!