Critical Flaw in Microsoft 365 OAuth Lets Attackers Steal Tokens
Key Takeaways Attackers are exploiting a vulnerability in Microsoft’s OAuth device authorization flow to steal authentication tokens. This “device code phishing” technique bypasses...
Key Takeaways
- Attackers are exploiting a vulnerability in Microsoft’s OAuth device authorization flow to steal authentication tokens.
- This “device code phishing” technique bypasses traditional security measures by operating entirely within legitimate Microsoft infrastructure.
- The threat, first identified by Proofpoint in early 2025, has seen a dramatic increase since late 2024, affecting organizations globally.
- Victims unknowingly grant full access to their Microsoft 365 accounts, enabling persistent access even after password changes.
- Mitigation includes conditional access policies, requiring compliant devices, and specialized user awareness training.
Attackers Leverage Microsoft 365 OAuth for Widespread Token Theft
A novel and increasingly prevalent attack vector is exploiting a fundamental aspect of Microsoft’s authentication ecosystem, allowing threat actors to compromise user credentials on a large scale. This technique, dubbed “device code phishing,” manipulates the OAuth device authorization flow, transforming a legitimate security feature into a potent tool for identity takeover.
Table Of Content
Security researchers have observed a significant surge in these campaigns since late 2024, catching many organizations off guard. The attacks are particularly insidious because they unfold entirely within trusted Microsoft infrastructure, making them exceptionally difficult for conventional security solutions to detect.
This evolution marks a critical shift in identity compromise tactics. While previously an obscure method, device code phishing is now routinely employed in various cybercriminal operations, from sophisticated business email compromise (BEC) schemes to corporate espionage. Data from 2023 to 2024 indicates a clear trend where attackers are abandoning traditional credential harvesting pages in favor of these more effective device code techniques.
Analysts at Proofpoint first documented this malicious activity in early 2025, detailing hundreds of campaigns targeting diverse industries. Their research, shared with Cyber Security News (CSN), highlights the unprecedented scale at which threat actors are gaining unauthorized access to Microsoft 365 accounts through this method. The inherent trust in official Microsoft services that this technique exploits makes it a formidable challenge for existing security defenses.
How Device Code Phishing Works
The core of device code phishing lies in its abuse of the OAuth 2.0 device authorization flow. This feature was originally designed to facilitate user authentication on input-constrained devices, such as smart TVs or gaming consoles. In a device code phishing attack, victims are lured to a genuine Microsoft page where they are prompted to enter a unique code. Unbeknownst to the user, this code has been generated by an attacker.
Upon entering the code, the system processes it as a legitimate authentication request. The victim inadvertently grants comprehensive access to their Microsoft 365 account, bypassing any suspicious login prompts typically associated with phishing attempts. Attackers commonly disseminate these device codes via social engineering tactics, including email campaigns that contain malicious PDF attachments, URLs, or QR codes that redirect to the official Microsoft device login page.
Once a target inputs the code within its 15-minute validity window, threat actors immediately acquire authentication tokens. These tokens provide persistent access to the victim’s account, rendering subsequent password changes ineffective in revoking the attacker’s access.
Compared to traditional credential phishing, this technique demands minimal technical expertise. Threat actors simply generate device codes using legitimate Microsoft APIs and then distribute them through social engineering. The seamless integration with Microsoft’s authentication systems ensures no overt red flags during the process. Phishing emails often impersonate common business services, pressuring recipients to act quickly by entering the provided code.
Escalating Threat Actor Adoption
Device code phishing has been adopted by various threat groups across multiple attack scenarios. Proofpoint researchers have documented campaigns by threat actor TA4903, who utilized device code phishing lures alongside CAPTCHA-themed social engineering in PDF attachments. This group specifically targeted small businesses and government entities, impersonating brands like Microsoft, DocuSign, and Norton.
Other prominent threat actors, including operators of EvilProxy, Storm-365, and groups employing the Kali 365 toolkit, have integrated device code phishing into their standard operational procedures. The Tycoon 2FA phishing kit has also incorporated device code capabilities, and researchers have observed the technique in campaigns linked to Russian cybercriminal infrastructure. Even cybersecurity-aware users find it challenging to identify these attacks, as the entire authentication process occurs on genuine Microsoft domains without any discernible suspicious indicators.
The proliferation of this technique accelerated following the emergence of proof-of-concept tools like ClickFix, which lowered the barrier to entry for less sophisticated criminals. What began as a method employed by advanced persistent threat (APT) groups has rapidly spread across the threat landscape, now appearing in campaigns targeting individuals and Fortune 500 enterprises alike.
What You Should Do
- Implement Conditional Access Policies: Block the device code flow where feasible through Microsoft 365 conditional access policies. This provides robust protection against unauthorized authentication attempts.
- Require Compliant/Managed Devices: Enforce policies that only allow authentication from compliant or managed devices, preventing access from uncontrolled endpoints.
- Enhance User Awareness Training: Develop and conduct specialized user awareness training programs that specifically address device code phishing attacks. Traditional phishing education often does not cover this nuanced threat vector.
- Monitor for Suspicious Activity: Regularly review authentication logs for unusual device code authentications or access from unfamiliar devices and locations.
- Review and Update Security Configurations: Ensure your Microsoft 365 tenant and Azure AD configurations are optimized for security, particularly around OAuth applications and device management.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.