GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts
Key Takeaways A new phishing kit, dubbed GhostCode, has been identified that bypasses Microsoft 365 Multi-Factor Authentication (MFA). GhostCode exploits the OAuth device authorization flow, tricking...
Key Takeaways
- A new phishing kit, dubbed GhostCode, has been identified that bypasses Microsoft 365 Multi-Factor Authentication (MFA).
- GhostCode exploits the OAuth device authorization flow, tricking users into approving a login for the attacker’s device rather than stealing passwords.
- The attack chain involves a sophisticated business email compromise (BEC) pretext, a password-protected HTML attachment, and a deceptive Microsoft device-code sign-in page.
- Attackers can gain a Primary Refresh Token (PRT) within seconds, allowing persistent access to Microsoft 365 services and the ability to register multiple malicious devices.
- Organizations should implement Conditional Access policies to restrict device-code authentication and educate users on the risks of unexpected device login requests.
A sophisticated new phishing toolkit, named GhostCode, is actively circumventing Microsoft 365 Multi-Factor Authentication (MFA) to compromise user accounts. This kit doesn’t rely on credential theft; instead, it manipulates victims into unwittingly authorizing a login for the attacker’s device, granting unauthorized access to their corporate accounts.
Table Of Content
The campaign initiates with seemingly innocuous messages delivered via business contact forms. Threat actors impersonate procurement personnel, subsequently requesting the target to sign a non-disclosure agreement (NDA). This request is then followed by a WeTransfer link containing a password-protected HTML attachment.
Upon opening the attachment, victims are presented with a convincing document-sharing lure that redirects them to a legitimate Microsoft device-code sign-in page. Security analysts at eSentire said in a report that they detected this activity in late August and subsequently named the kit GhostCode. The name reflects both the kit’s obfuscated code and its utilization of infrastructure linked to GHOSTnet during the device enrollment process.
The immediate danger of GhostCode lies in its method: victims perform their authentication, including MFA, on an authentic Microsoft domain. This process grants the GhostCode kit a valid authentication token, which it then uses to redirect the victim to a decoy NDA document. The attackers can then begin exploiting the compromised account before the victim even realizes a breach has occurred. This tactic highlights the difficulty in detecting device-code phishing campaigns using traditional indicators of password theft.
The campaign demonstrates how attackers can leverage user trust in familiar identity pages, rather than exploiting technical vulnerabilities, to their advantage. For organizations heavily reliant on cloud services, a seemingly routine approval request can rapidly escalate into a critical account security incident, often before security teams can fully investigate initial alerts.
GhostCode Phishing Kit Bypasses Microsoft 365 MFA
GhostCode exploits the OAuth device authorization flow, a mechanism designed for input-constrained devices like smart TVs that cannot easily display full login screens. The attacker’s server requests a device code using the Microsoft Authentication Broker application ID. This code is then embedded into a meticulously crafted, fake document portal, prompting the target to authenticate it. Essentially, the user is tricked into authorizing the attacker’s device to access their Microsoft 365 account.
Further complicating detection, the initial HTML attachment is heavily obfuscated. It is padded with irrelevant data, its visible text is fragmented with HTML comments, and the redirection URL remains encrypted until the correct password is entered. Once the victim reaches the phishing server, a browser challenge and geographical location checks are performed to deter automated scanners. This multi-layered approach to evasion mirrors techniques observed in the EvilTokens phishing service, but GhostCode enhances it with targeted outreach via business contact forms.
Once the sign-in is approved, the kit utilizes residential proxy addresses that correspond to the victim’s geographical location. This tactic minimizes suspicion by making the Microsoft authentication prompt appear routine and can bypass location-based security alerts. In a documented intrusion, attackers executed nine successful API calls, registered three devices within 78 seconds, and acquired a Primary Refresh Token (PRT) in just 32 seconds. This PRT grants persistent single sign-on capabilities across all Microsoft 365 services without requiring further user authentication.
Containing a Fast-Moving Identity Attack
The rapid nature of this attack means that simply revoking a stolen token may not be sufficient to secure the environment, as devices already registered within the tenant could remain active. Researchers discovered that enrolled devices persist until explicitly disabled or removed by administrators. Therefore, incident response teams addressing suspicious device-code activity must invalidate all relevant tokens, reset affected user credentials, meticulously review newly registered devices, and thoroughly check mail and cloud-access logs for any subsequent malicious activity.
The primary recommended mitigation is to implement Conditional Access policies to block device-code authentication for all users who do not have a genuine business need for it. Organizations should establish tightly defined exceptions for approved service accounts or provisioning workflows. Additionally, applying device-compliance controls can further reduce the attack surface, limiting the number of employees susceptible to similar tactics seen in passkey-themed phishing attacks.
Security teams should configure alerts for successful device-code authentication events followed by anomalous scripted requests or multiple device registrations from a single non-interactive session. They should also actively search for device names conforming to a pattern of “first-name, last-name, company-domain, and hexadecimal suffix.” User awareness remains a critical defense: any unexpected request to enter a code into a Microsoft page should be treated with extreme suspicion, especially as Microsoft 365 session theft campaigns increasingly target authentication tokens rather than traditional passwords.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | bjssourcing[.]com |
Lookalike sender domain used in the procurement-officer pretext |
| Domain | greenlightdlstribution[.]com |
Related impersonation domain registered during the campaign period |
| Email address | jeremyarcher@voewo[.]com |
Disposable address associated with registration of a related lookalike domain |
| Domain | voewo[.]com |
Domain tied to disposable registration personas |
| File name | 3arhCt9c0p.html |
Password-protected HTML attachment used as the document-sharing lure |
| URL | hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d106d7 |
Decrypted relay URL used for tracking, filtering, and redirection |
| URL path | /scanna/file001// |
Additional observed campaign path on the same relay infrastructure |
| Domain | chartered.flipbookonlinevault[.]com |
Relay and bot-filtering infrastructure hosting the encrypted redirect destination |
| Domain | account-access-rc3uenqi.elitechiropracticandrehab[.]com |
Device-code phishing server hosted under a likely compromised site |
| URL path | /turnstile?return_url=%2F3OnOQubA2bS4o26p3MRXyYV3XuUZ6... |
Cloudflare Turnstile path used before serving the phishing portal |
| API path | /api/harvester?action=geoip |
Backend request used to assess victim location and set proxy routing |
| API path | /api/harvester?action=get_code |
Backend request used to obtain a device authorization code |
| API path | /api/harvester?action=poll |
Backend request used to poll for completed device authentication |
| Application ID | 29d9ed98-a469-4536-ade2-f981bc1d605e |
Microsoft Authentication Broker application ID abused in the device-code flow |
| User-Agent | python-requests/2.34.2 |
Scripted request signature seen during token use and post-authentication activity |
| IP address | 82.33.39[.]74 |
Residential proxy IP observed during token use |
| IP address | 151.225.227[.]193 |
Residential proxy IP observed during token use |
| IP address | 176.253.248[.]175 |
Residential proxy IP observed during token use |
| IP address | 94.9.97[.]142 |
Residential proxy IP observed during token use |
| IP address | 86.132.13[.]219 |
Residential proxy IP observed during token use |
| IP address | 81.96.174[.]54 |
Residential proxy IP observed during token use |
| IP address | 90.215.55[.]70 |
Residential proxy IP observed during token use |
| IP address | 92.40.47[.]84 |
Residential proxy IP observed during token use |
| IP address | 5.230.71[.]51 |
GHOSTnet-associated IP observed during final Intune enrolment |
| Device ID | 4e537622-2514-48b8-84ed-0139549cfab0 |
First attacker-registered device |
| Device ID | 6c290bcc-62d3-40bd-a774-816109af6729 |
Second attacker-registered device |
| Device ID | 5e83a216-f67e-43b8-a129-f67666a001dd |
Third attacker-registered device, later enrolled in Intune <a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7d1b1bd4-0f25-4dee-abdc-b34a1330e08e/GhostCode-Phishing-Kit-Bypasses-Microsoft-365-MFA-to-Hijack-Accounts-in-78-Seconds.pdf?AWSAccessKeyId=ASIA2F3EMEYE6O44HXCN&Signature=42TynF2GHssCt5CXMNjusuIO8Io%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEE8aCXVzLWVhc3QtMSJGMEQCIGzeKWmBLvQMG7ugmw65qI7K55nY2ApaiSXqs%2FtXX4MdAiAgXEaHZImLX18AUAZ1FyLKhNIgNFd28Sl7WvhdCRQTFyrzBAgXEAEaDDY5OTc1MzMwOTcwNSIMDVlPuCRM592eGhIsKtAEDbILMysFaBK0zkmPRVE%2Bcbn9x9dKeUulv9x5cHCCWqtRgeQ%2FmpuhLH9KIC0JSCKynT87VAkYkzmyO9TfHu3%2BKH4Lrd8bvXgl5eW3OLrJFiDNy85%2FectTtT5B%2BS4%2FbAUZ4cfCWKA1Ts6bzO5g9YwDWj929RsVXFIoMgL7V0%2FN18L0lf%2Fiycs2Mbu4KXxhIEd403NfosCU4LIJlR12%2FyBjN5GgOTmeVxoVZklZofV%2BmYmr%2FB54BEcthsS7p2Le1CdhqJoyulER6YreKZadSSdx57gSpED74RClelOJlu1%2FfP9%2BfIo3AbP94gN%2BEKuZIwY8SfOhfmovqE6zkzLIhyTlK5rCNLTtHBO3JO8wMmVt%2BPQwUqlew%2FrgNZZjVBmJUlymduAo9c44KedwZUR4uzXDO7BAXXwb4aDxwlFP7zVulM41Ol4gDe6D2zhf3zC0S1HKlwYmzUD3jKl1MJGFFqQ4V9L1qSkT01Ewx9JCbTrX7z%2B3zfo%2BWU%2F5fgqEQQ6fKho29KqDeZlTM3a2i2N%2BlVWKUwV0xnGVtU21xuRMnTWYNIQEkJFyCa9ah4SwVgR4hjnuI4EJj%2B8p2vQQXCXkMunTEJhxlPVw7jCV%2FGV3LujAuZa0pzETzj17Pp%2Fwfucz8tVUnArRZ%2BTHbzSdFRI7E0jyYCCykxHNIBM49r4GeJipW0jQYdmlgq%2B%2FusqbdUMOZ%2BC5xYFetTlZLxEcerdJZMwhlR1vmrbb5Ldw5Hvyp9t5TTnWmxA08NuQzbvhOTc5ADQxLhgeaGF%2B708pmmlQaB3h9DDhyKrVBjqZASR6%2FCvgMs7ARBdQxKxVsY81CkSILEWNnhEEmT7ongbgChbOZRpgDxCMvP5fF2mQRvNqnphhOuf5qg0mB1YrUGF%2BPxJ3COxcxz0Byn1WZ6Nok3rOUfnO7rS8Fu
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.