Inside an AIenabled device code phishing campaign
Essential information
- Published
- 06/04/2026 20:28
- Modified
- 06/04/2026 21:48
- Tags
- 2026-04-06 phishing
- Related entities
- 1 techniques (mitre), 1 malware, 3 others
Description
Microsoft Defender Security Research has observed a widespread phishing campaign leveraging the Device Code Authentication flow to compromise organizational accounts at scale. While traditional device code attacks are typically narrow in scope, this campaign demonstrated a higher success rate, driven by automation and dynamic code generation that circumvented the standard 15-minute expiration window for device codes. This activity aligns with the emergence of EvilToken, a Phishing-as-a-Service (PhaaS) toolkit identified as a key driver of large-scale device code abuse.