216.73.217.22

Microsoft OAuth Device Code Phishing

· Published 11/03/2026 06:17 · Modified 11/03/2026 10:36

Export JSON

Essential information

Published
11/03/2026 06:17
Modified
11/03/2026 10:36
Tags
2026-03-11 account takeover device code https microsoft 365 oauth phishing ssl decryption token-based
Related entities
1 techniques (mitre), 9 others

Description

A new technique abusing Microsoft's flow is on the rise, with over 180 URLs detected in a week. This method shifts from credential theft to , making detection more challenging. Attackers initiate a device authorization process, tricking victims into approving it on legitimate Microsoft pages. The attack uses encrypted traffic and legitimate authentication flows, bypassing traditional indicators. Victims unknowingly grant attackers access to their accounts through tokens. This poses a critical risk as it allows immediate access to corporate data and resources, potentially leading to business email compromise and persistent access through refresh tokens.

External references