216.73.217.22

Abusing OAuth Device Code Flow

· Published 20/04/2026 22:30 · Modified 21/04/2026 09:27

Export JSON

Essential information

Published
20/04/2026 22:30
Modified
21/04/2026 09:27
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
credential theft device code flow graph api microsoft entra id oauth persistent access phishing token hijacking
Tags
2026-04-20 credential-theft device code flow graph api microsoft entra id oauth persistent access phishing token hijacking
Related entities
3 indicators, 3 observables, 19 techniques (mitre), 1 others

Description

In early 2026, attacks remain a top threat vector in security operations. This analysis covers a novel attack method exploiting Microsoft's 2.0 Device Authorization Grant () to compromise user accounts. Attackers use emails containing Mailchimp's Mandrill service links to bypass security controls, leading victims to fake Adobe-themed websites. The sites abuse legitimate Microsoft authentication mechanisms to obtain access and refresh tokens, granting persistent delegated access to critical resources like , Teams, Outlook, and SharePoint. The technique leverages shared client IDs across tenants and family of client IDs (FOCI) for lateral movement. Two variants exist: one using external infrastructure with dynamic code generation, and another relying solely on fake meeting invitations containing pre-generated device codes. The attack is particularly effective as it uses legitimate Microsoft services, making detection challenging.

External references