216.73.217.24

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

· Published 23/07/2026 09:30

Export JSON

Essential information

Published
23/07/2026 09:30
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
authentication broker device code phishing email account takeover mfa bypass microsoft 365 compromise oauth 2.0 abuse session hijacking spearphishing
Related entities
8 indicators, 8 observables

Description

exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints.

External references