Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft 365 Suffers Widespread Outage with 502 and 503 Errors
September 16, 2026
VectraRAT Malware for Rent, Threatens Windows PCs
September 16, 2026
GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts
September 16, 2026
Home/Threats/GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts
Threats

GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts

Key Takeaways A new phishing kit, dubbed GhostCode, has been identified that bypasses Microsoft 365 Multi-Factor Authentication (MFA). GhostCode exploits the OAuth device authorization flow, tricking...

Marcus Rodriguez
Marcus Rodriguez
September 16, 2026 5 Min Read
2 0

Key Takeaways

  • A new phishing kit, dubbed GhostCode, has been identified that bypasses Microsoft 365 Multi-Factor Authentication (MFA).
  • GhostCode exploits the OAuth device authorization flow, tricking users into approving a login for the attacker’s device rather than stealing passwords.
  • The attack chain involves a sophisticated business email compromise (BEC) pretext, a password-protected HTML attachment, and a deceptive Microsoft device-code sign-in page.
  • Attackers can gain a Primary Refresh Token (PRT) within seconds, allowing persistent access to Microsoft 365 services and the ability to register multiple malicious devices.
  • Organizations should implement Conditional Access policies to restrict device-code authentication and educate users on the risks of unexpected device login requests.

A sophisticated new phishing toolkit, named GhostCode, is actively circumventing Microsoft 365 Multi-Factor Authentication (MFA) to compromise user accounts. This kit doesn’t rely on credential theft; instead, it manipulates victims into unwittingly authorizing a login for the attacker’s device, granting unauthorized access to their corporate accounts.

Table Of Content

  • Key Takeaways
  • GhostCode Phishing Kit Bypasses Microsoft 365 MFA
  • Containing a Fast-Moving Identity Attack

The campaign initiates with seemingly innocuous messages delivered via business contact forms. Threat actors impersonate procurement personnel, subsequently requesting the target to sign a non-disclosure agreement (NDA). This request is then followed by a WeTransfer link containing a password-protected HTML attachment.

Upon opening the attachment, victims are presented with a convincing document-sharing lure that redirects them to a legitimate Microsoft device-code sign-in page. Security analysts at eSentire said in a report that they detected this activity in late August and subsequently named the kit GhostCode. The name reflects both the kit’s obfuscated code and its utilization of infrastructure linked to GHOSTnet during the device enrollment process.

The immediate danger of GhostCode lies in its method: victims perform their authentication, including MFA, on an authentic Microsoft domain. This process grants the GhostCode kit a valid authentication token, which it then uses to redirect the victim to a decoy NDA document. The attackers can then begin exploiting the compromised account before the victim even realizes a breach has occurred. This tactic highlights the difficulty in detecting device-code phishing campaigns using traditional indicators of password theft.

The campaign demonstrates how attackers can leverage user trust in familiar identity pages, rather than exploiting technical vulnerabilities, to their advantage. For organizations heavily reliant on cloud services, a seemingly routine approval request can rapidly escalate into a critical account security incident, often before security teams can fully investigate initial alerts.

GhostCode Phishing Kit Bypasses Microsoft 365 MFA

GhostCode exploits the OAuth device authorization flow, a mechanism designed for input-constrained devices like smart TVs that cannot easily display full login screens. The attacker’s server requests a device code using the Microsoft Authentication Broker application ID. This code is then embedded into a meticulously crafted, fake document portal, prompting the target to authenticate it. Essentially, the user is tricked into authorizing the attacker’s device to access their Microsoft 365 account.

Further complicating detection, the initial HTML attachment is heavily obfuscated. It is padded with irrelevant data, its visible text is fragmented with HTML comments, and the redirection URL remains encrypted until the correct password is entered. Once the victim reaches the phishing server, a browser challenge and geographical location checks are performed to deter automated scanners. This multi-layered approach to evasion mirrors techniques observed in the EvilTokens phishing service, but GhostCode enhances it with targeted outreach via business contact forms.

Once the sign-in is approved, the kit utilizes residential proxy addresses that correspond to the victim’s geographical location. This tactic minimizes suspicion by making the Microsoft authentication prompt appear routine and can bypass location-based security alerts. In a documented intrusion, attackers executed nine successful API calls, registered three devices within 78 seconds, and acquired a Primary Refresh Token (PRT) in just 32 seconds. This PRT grants persistent single sign-on capabilities across all Microsoft 365 services without requiring further user authentication.

Containing a Fast-Moving Identity Attack

The rapid nature of this attack means that simply revoking a stolen token may not be sufficient to secure the environment, as devices already registered within the tenant could remain active. Researchers discovered that enrolled devices persist until explicitly disabled or removed by administrators. Therefore, incident response teams addressing suspicious device-code activity must invalidate all relevant tokens, reset affected user credentials, meticulously review newly registered devices, and thoroughly check mail and cloud-access logs for any subsequent malicious activity.

The primary recommended mitigation is to implement Conditional Access policies to block device-code authentication for all users who do not have a genuine business need for it. Organizations should establish tightly defined exceptions for approved service accounts or provisioning workflows. Additionally, applying device-compliance controls can further reduce the attack surface, limiting the number of employees susceptible to similar tactics seen in passkey-themed phishing attacks.

Security teams should configure alerts for successful device-code authentication events followed by anomalous scripted requests or multiple device registrations from a single non-interactive session. They should also actively search for device names conforming to a pattern of “first-name, last-name, company-domain, and hexadecimal suffix.” User awareness remains a critical defense: any unexpected request to enter a code into a Microsoft page should be treated with extreme suspicion, especially as Microsoft 365 session theft campaigns increasingly target authentication tokens rather than traditional passwords.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain bjssourcing[.]com Lookalike sender domain used in the procurement-officer pretext
Domain greenlightdlstribution[.]com Related impersonation domain registered during the campaign period
Email address jeremyarcher@voewo[.]com Disposable address associated with registration of a related lookalike domain
Domain voewo[.]com Domain tied to disposable registration personas
File name 3arhCt9c0p.html Password-protected HTML attachment used as the document-sharing lure
URL hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d106d7 Decrypted relay URL used for tracking, filtering, and redirection
URL path /scanna/file001// Additional observed campaign path on the same relay infrastructure
Domain chartered.flipbookonlinevault[.]com Relay and bot-filtering infrastructure hosting the encrypted redirect destination
Domain account-access-rc3uenqi.elitechiropracticandrehab[.]com Device-code phishing server hosted under a likely compromised site
URL path /turnstile?return_url=%2F3OnOQubA2bS4o26p3MRXyYV3XuUZ6... Cloudflare Turnstile path used before serving the phishing portal
API path /api/harvester?action=geoip Backend request used to assess victim location and set proxy routing
API path /api/harvester?action=get_code Backend request used to obtain a device authorization code
API path /api/harvester?action=poll Backend request used to poll for completed device authentication
Application ID 29d9ed98-a469-4536-ade2-f981bc1d605e Microsoft Authentication Broker application ID abused in the device-code flow
User-Agent python-requests/2.34.2 Scripted request signature seen during token use and post-authentication activity
IP address 82.33.39[.]74 Residential proxy IP observed during token use
IP address 151.225.227[.]193 Residential proxy IP observed during token use
IP address 176.253.248[.]175 Residential proxy IP observed during token use
IP address 94.9.97[.]142 Residential proxy IP observed during token use
IP address 86.132.13[.]219 Residential proxy IP observed during token use
IP address 81.96.174[.]54 Residential proxy IP observed during token use
IP address 90.215.55[.]70 Residential proxy IP observed during token use
IP address 92.40.47[.]84 Residential proxy IP observed during token use
IP address 5.230.71[.]51 GHOSTnet-associated IP observed during final Intune enrolment
Device ID 4e537622-2514-48b8-84ed-0139549cfab0 First attacker-registered device
Device ID 6c290bcc-62d3-40bd-a774-816109af6729 Second attacker-registered device
Device ID 5e83a216-f67e-43b8-a129-f67666a001dd Third attacker-registered device, later enrolled in Intune <a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/7d1b1bd4-0f25-4dee-abdc-b34a1330e08e/GhostCode-Phishing-Kit-Bypasses-Microsoft-365-MFA-to-Hijack-Accounts-in-78-Seconds.pdf?AWSAccessKeyId=ASIA2F3EMEYE6O44HXCN&Signature=42TynF2GHssCt5CXMNjusuIO8Io%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEE8aCXVzLWVhc3QtMSJGMEQCIGzeKWmBLvQMG7ugmw65qI7K55nY2ApaiSXqs%2FtXX4MdAiAgXEaHZImLX18AUAZ1FyLKhNIgNFd28Sl7WvhdCRQTFyrzBAgXEAEaDDY5OTc1MzMwOTcwNSIMDVlPuCRM592eGhIsKtAEDbILMysFaBK0zkmPRVE%2Bcbn9x9dKeUulv9x5cHCCWqtRgeQ%2FmpuhLH9KIC0JSCKynT87VAkYkzmyO9TfHu3%2BKH4Lrd8bvXgl5eW3OLrJFiDNy85%2FectTtT5B%2BS4%2FbAUZ4cfCWKA1Ts6bzO5g9YwDWj929RsVXFIoMgL7V0%2FN18L0lf%2Fiycs2Mbu4KXxhIEd403NfosCU4LIJlR12%2FyBjN5GgOTmeVxoVZklZofV%2BmYmr%2FB54BEcthsS7p2Le1CdhqJoyulER6YreKZadSSdx57gSpED74RClelOJlu1%2FfP9%2BfIo3AbP94gN%2BEKuZIwY8SfOhfmovqE6zkzLIhyTlK5rCNLTtHBO3JO8wMmVt%2BPQwUqlew%2FrgNZZjVBmJUlymduAo9c44KedwZUR4uzXDO7BAXXwb4aDxwlFP7zVulM41Ol4gDe6D2zhf3zC0S1HKlwYmzUD3jKl1MJGFFqQ4V9L1qSkT01Ewx9JCbTrX7z%2B3zfo%2BWU%2F5fgqEQQ6fKho29KqDeZlTM3a2i2N%2BlVWKUwV0xnGVtU21xuRMnTWYNIQEkJFyCa9ah4SwVgR4hjnuI4EJj%2B8p2vQQXCXkMunTEJhxlPVw7jCV%2FGV3LujAuZa0pzETzj17Pp%2Fwfucz8tVUnArRZ%2BTHbzSdFRI7E0jyYCCykxHNIBM49r4GeJipW0jQYdmlgq%2B%2FusqbdUMOZ%2BC5xYFetTlZLxEcerdJZMwhlR1vmrbb5Ldw5Hvyp9t5TTnWmxA08NuQzbvhOTc5ADQxLhgeaGF%2B708pmmlQaB3h9DDhyKrVBjqZASR6%2FCvgMs7ARBdQxKxVsY81CkSILEWNnhEEmT7ongbgChbOZRpgDxCMvP5fF2mQRvNqnphhOuf5qg0mB1YrUGF%2BPxJ3COxcxz0Byn1WZ6Nok3rOUfnO7rS8Fu

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Noodle RAT Malware Targets Windows, Linux Systems for Remote Control

Next Post

VectraRAT Malware for Rent, Threatens Windows PCs

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Oracle Q3 2023 Critical Patch Update: 673 Vulnerabilities Fixed
September 16, 2026
Critical Issabel PBX RCE actively exploited, patch immediately
September 16, 2026
Critical HPE RMC, OneView, and iLO 5 Flaws Let Attackers Remotely Execute Code
September 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us