216.73.216.6

Inside an AIenabled device code phishing campaign

· Published 06/04/2026 20:28 · Modified 06/04/2026 21:48

Export JSON

Essential information

Published
06/04/2026 20:28
Modified
06/04/2026 21:48
Tags
2026-04-06 phishing
Related entities
1 techniques (mitre), 1 malware, 3 others

Description

Microsoft Defender Security Research has observed a widespread campaign leveraging the Device Code Authentication flow to compromise organizational accounts at scale. While traditional device code attacks are typically narrow in scope, this campaign demonstrated a higher success rate, driven by automation and dynamic code generation that circumvented the standard 15-minute expiration window for device codes. This activity aligns with the emergence of EvilToken, a -as-a-Service (PhaaS) toolkit identified as a key driver of large-scale device code abuse.

External references