Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited
June 16, 2026
Threat Intelligence: When Do IOCs Stop Being Useful
June 16, 2026
India Temporarily Bans Telegram Over Medical Exam Fraud
June 16, 2026
Home/Threats/Microsoft 365 Device Code Phishing Byp Campaign Bypasses
Threats

Microsoft 365 Device Code Phishing Byp Campaign Bypasses

A recently uncovered phishing campaign is targeting Microsoft 365 users, employing a novel approach distinct from typical attacks. Instead of trying to steal a victim’s password directly, this...

Emy Elsamnoudy
Emy Elsamnoudy
June 16, 2026 5 Min Read
3 0

A recently uncovered phishing campaign is targeting Microsoft 365 users, employing a novel approach distinct from typical attacks.

Instead of trying to steal a victim’s password directly, this campaign tricks users into completing a real Microsoft authentication process that quietly hands over control of their account to an attacker.

It is a convincing technique that is becoming harder for everyday users to recognize. The method at the center of this campaign is called Device Code phishing.

In a normal, legitimate scenario, Microsoft’s Device Code flow helps users authenticate on devices where typing a username and password is inconvenient, such as a smart TV or a command-line tool.

The attacker here has turned that helpful feature into a trap, using it to authorize their own controlled device to access the victim’s account without ever collecting a password.

Analysts at ReversingLabs identified and documented this active campaign, noting that it combines realistic business-themed lure emails, a polished phishing kit, and Microsoft’s own Device Authorization Grant flow to carry out a near-invisible account takeover.

ReversingLabs researchers said in a report, shared with Cyber Security News (CSN), reveals how threat actors have refined this technique to bypass standard defenses and make the attack appear as a routine Microsoft login.

The attack starts with an email that looks like an approval request from a vendor or a business contact. Attached is an image that, when clicked, redirects the victim to a fake landing page mimicking a genuine Microsoft design.

From there, the victim is asked to copy a short code and enter it on the real Microsoft device login page. Most people have no reason to suspect anything unusual at this point.

Device Code phishing lure image (Source - ReversinLabs)
Device Code phishing lure image (Source – ReversinLabs)

Once the code is entered and the victim signs in, Microsoft’s authentication system authorizes the attacker’s device. The victim sees nothing out of the ordinary.

The attacker now holds a valid access token for that Microsoft 365 account and can use it to read emails, access files, and move laterally inside a target organization.

Microsoft 365 Device Code Phishing Campaign

The phishing kit behind this campaign is built to evade automated detection.

The landing pages embed invisible Unicode characters, including Zero Width Space, Word Joiner, and Zero Width Non-Joiner, scattered throughout words that security tools flag as phishing indicators.

Device code phishing landing page (Source - ReversingLabs)
Device code phishing landing page (Source – ReversingLabs)

This makes the pages difficult to catch through standard signature matching. The kit uses a URL hosted on Akamai’s legitimate infrastructure as the device login entry point, adding to its appearance of legitimacy.

A POST request is sent from the kit’s backend to the phishing host every four seconds, coordinating the OAuth flow between the attacker and the authentication session the victim is completing. This steady beacon is one of the few detectable signs of the attack.

Device code POST request to phishing kit host (Source - ReversingLabs)
Device code POST request to phishing kit host (Source – ReversingLabs)

The network traffic produced by the kit can also help with detection. Two sequences of hostname resolutions tied to the phishing landing page and the Microsoft authentication flow form identifiable clusters.

A third cluster is beacon activity sent every four seconds after the first authentication phase begins, giving security teams a reliable signal to hunt for in their network logs.

Defending Against Device Code Phishing

ReversingLabs has released a YARA rule to detect the landing pages used by this phishing kit.

The rule identifies combinations of invisible Unicode characters alongside encoded authentication token artifacts in page source code.

When paired with network-based hunting using the traffic patterns described in the report, defenders have a strong starting point.

Organizations should train employees to question any prompt asking them to copy and paste a code into a Microsoft login page.

Monitoring Entra ID sign-in logs for Device Code grant usage is recommended, especially where the sign-in originates from an endpoint that is not a known IoT or command-line device.

Security teams should deploy detections for phishing kit artifacts outlined in the ReversingLabs report, including landing page indicators and the network traffic pattern tied to this attack.

Indicators of Compromise (IoCs):-

Type Indicator Description
URL hxxp[://]ajz-gud[.]lisa-g-h-rn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]baquelite[.]ventoraco[.]com/doc98374/ Phishing kit landing page
URL hxxp[://]biotechgroup[.]p-oye8mc0f[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]bradhallfuel[.]p-oye8mc0f[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]corpexl[.]nl/mq5qh1xj9/ Phishing kit landing page
URL hxxp[://]corpexl[.]nl/oii/ Phishing kit landing page
URL hxxp[://]corpexl[.]nl/projectorder/ Phishing kit landing page
URL hxxp[://]creditora[.]me[.]uk/HPDGassocies Phishing kit landing page
URL hxxp[://]dentalstrategies[.]noventragroup[.]app/dntrategie/ Phishing kit landing page
URL hxxp[://]docxfile-share[.]itkljpqn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]docxfiletxz-share[.]itkljpqn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]gsbauwu1hsa[.]legalaro[.]com/nmasn/ Phishing kit landing page
URL hxxp[://]henriquevieira[.]horizoralabs[.]com/doc49390239/ Phishing kit landing page
URL hxxp[://]horizonex[.]it[.]com/confidentialrecord/ Phishing kit landing page
URL hxxp[://]horizonex[.]it[.]com/securedocument Phishing kit landing page
URL hxxp[://]hsecontractors-project[.]sign-ins[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]logvault[.]us/jfkydg4of/ Phishing kit landing page
URL hxxp[://]mcagroup[.]horizoralabs[.]com/quote937847/ Phishing kit landing page
URL hxxp[://]meeting[.]corpsfileshare[.]com/quarterly/ Phishing kit landing page
URL hxxp[://]metroraco[.]com/GroupeBergeron/ Phishing kit landing page
URL hxxp[://]metroraco[.]com/Vent/ Phishing kit landing page
URL hxxp[://]microsoft-document[.]adhere[.]it[.]com/Adobe-pdf/ Phishing kit landing page
URL hxxp[://]molinomerano[.]brieflync[.]nl/order9283/ Phishing kit landing page
URL hxxp[://]mysharereport[.]wgmilshyvn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]onedrive-document[.]adhere[.]it[.]com/sharedproject/ Phishing kit landing page
URL hxxp[://]retroactive[.]scalevantaco[.]com/adjustments Phishing kit landing page
URL hxxp[://]review[.]wgmilshyvn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]sales[.]p-ct5v25xo[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]samoen[.]logvault[.]us/engineering Phishing kit landing page
URL hxxp[://]sparkaxis[.]org/deployment/ Phishing kit landing page
URL hxxp[://]tsk1[.]t31208026[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]uboralmaxillofacialsurgery[.]noventragroup[.]app/uboralxillofia Phishing kit landing page
URL hxxp[://]uegreil[.]taskvault[.]nl/itiwa2 Phishing kit landing page
URL hxxp[://]v379ge[.]meetrova[.]nl/p9mxbmz2x/ Phishing kit landing page
URL hxxp[://]wpdoi8w[.]elevatecore[.]it[.]com/g4jlitpi/ Phishing kit landing page
URL hxxp[://]wylderhotels[.]sparkaxis[.]org/personaljflannigan/ Phishing kit landing page
URL hxxp[://]zktxnxlh[.]stratavaco[.]com/snzv8wq Phishing kit landing page
URL hxxps[://]adhere[.]it[.]com/verify/ Phishing kit landing page
URL hxxps[://]apexviaco[.]com/code/ Phishing kit landing page
URL hxxps[://]corpexl[.]nl/INV/ Phishing kit landing page
URL hxxps[://]corpexl[.]nl/PO/ Phishing kit landing page
URL hxxps[://]corpexl[.]nl/securee/ Phishing kit landing page
URL hxxps[://]covenant[.]it[.]com/Project/ Phishing kit landing page
URL hxxps[://]creditora[.]me[.]uk/NorthShore/ Phishing kit landing page
URL hxxps[://]docusign-arizonacreativeevents[.]nextvexharbor[.]de/review/ Phishing kit landing page
URL hxxps[://]docusign-stlequityhomes[.]nextvexharbor[.]de/review/ Phishing kit landing page
URL hxxps[://]fortknox[.]noventragroup[.]app/fortknoxxx/ Phishing kit landing page
URL hxxps[://]growthora[.]app/doc/ Phishing kit landing page
URL hxxps[://]horizonex[.]it[.]com/confidentialfile/ Phishing kit landing page
URL hxxps[://]login[.]growthora[.]app/document/ Phishing kit landing page
URL hxxps[://]meeting[.]corpsfileshare[.]com/quarterly/ Phishing kit landing page
URL hxxps[://]metroraco[.]com/Desjardinsh/ Phishing kit landing page
URL hxxps[://]metroraco[.]com/InnovativePipeline/ Phishing kit landing page
URL hxxps[://]momentoraco[.]com/Project-submittal/ Phishing kit landing page
URL hxxps[://]momentoraco[.]com/project-document/ Phishing kit landing page
URL hxxps[://]my-team-share[.]corpsfileshare[.]com/team/ Phishing kit landing page
URL hxxps[://]nexttrail[.]co[.]nl/m365scoft/ Phishing kit landing page
URL hxxps[://]onedrive-encrypted-online[.]clearledge[.]me[.]uk/avc8xt/ Phishing kit landing page
URL hxxps[://]onedrive-encrypted[.]clearledge[.]me[.]uk/aar0cphl/ Phishing kit landing page
URL hxxps[://]onedrive-microsoft[.]adhere[.]it[.]com/securedocument/ Phishing kit landing page
URL hxxps[://]payroll[.]vardeno[.]nl/employee/ Phishing kit landing page
URL hxxps[://]ringcentral[.]firmtix[.]com/alert/ Phishing kit landing page
URL hxxps[://]ringcentral[.]firmtix[.]com/notify/ Phishing kit landing page
URL hxxps[://]secure[.]firmtix[.]com/docx Phishing kit landing page
URL hxxps[://]sparkaxis[.]org/delivery/ Phishing kit landing page
URL hxxps[://]sparkaxis[.]org/statement/ Phishing kit landing page
URL hxxps[://]stratifylabs[.]org/BDAGroup/ Phishing kit landing page
URL hxxps[://]stratifylabs[.]org/FACTURE/ Phishing kit landing page
URL hxxps[://]teams[.]vardeno[.]nl/fileshared/ Phishing kit landing page
URL hxxps[://]trenix[.]nl/alma-resort/ Phishing kit landing page
URL hxxps[://]verif[.]futureanchor[.]it[.]com/cloud/ Phishing kit landing page
URL hxxps[://]verification[.]futureanchor[.]it[.]com/cardcrosoft/ Phishing kit landing page
URL hxxps[://]vmservfill[.]nkydzvws[.]workers[.]dev/ Phishing kit landing page
Network Hostname login.microsoftonline.com Legitimate Microsoft authentication endpoint abused in Device Code flow
Network Hostname aka.ms/devicelogin Legitimate Microsoft device login URL referenced in phishing lures
Network Hostname login.live.com/oauth20_remoteconnect.srf Legitimate Microsoft Live auth endpoint abused in phishing kit
YARA Rule DeviceCode_Phishing_LandingPageHTML YARA detection rule for Device Code phishing kit landing pages (authored by Malware Utkonos, dated 2026-05-20)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Hackers Weaponize Microsoft Teams Relay to Conceal Malware Traffic

Next Post

India Temporarily Bans Telegram Over Medical Exam Fraud

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Interlock & Rhysida Ransomware Share Supper Backdoor
June 16, 2026
Novo Nordisk Cyber Attack: Patient Data & AI Confirms Hackers
June 16, 2026
Russian & Chinese AI Evade Bot Detection, Mimic Humans
June 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us