Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical FortiGate RCE CVE-2022-42475 Exploited in Polish Energy Sector Attack
August 11, 2026
GhostJacking Attack Hijacks AI Agents to Run Malicious Code on Developer Machines
August 11, 2026
Horizon3.ai Secures $20M to Boost Partner-Led Growth and Ecosystem
August 11, 2026
Home/Threats/Microsoft 365 Device Code Phishing Bypasses MFA for Account Takeover
Threats

Microsoft 365 Device Code Phishing Bypasses MFA for Account Takeover

Key Takeaways A sophisticated phishing campaign is actively targeting Microsoft 365 users. The attack exploits Microsoft’s legitimate Device Code authentication flow, bypassing traditional MFA...

Emy Elsamnoudy
Emy Elsamnoudy
June 16, 2026 6 Min Read
49 0

Key Takeaways

  • A sophisticated phishing campaign is actively targeting Microsoft 365 users.
  • The attack exploits Microsoft’s legitimate Device Code authentication flow, bypassing traditional MFA protections.
  • Threat actors gain full account control without ever stealing a password, making detection difficult for users.
  • Security researchers have identified unique indicators of compromise (IoCs), including specific network traffic patterns and a YARA rule for detection.

Microsoft 365 Device Code Phishing Campaign Bypasses MFA

A new, highly effective phishing campaign has emerged, targeting Microsoft 365 users by exploiting a legitimate authentication feature to gain unauthorized account access. This method, termed Device Code phishing, represents a significant evolution from typical password-stealing attacks, as it allows attackers to bypass multi-factor authentication (MFA) and seize control of accounts without ever directly asking for user credentials.

Table Of Content

  • Key Takeaways
  • Microsoft 365 Device Code Phishing Campaign Bypasses MFA
  • How the Device Code Phishing Attack Works
  • Advanced Phishing Kit Evades Detection
  • What You Should Do
  • Indicators of Compromise (IoCs):-

Instead of attempting to trick users into divulging their passwords on a fake login page, this campaign manipulates victims into unknowingly completing a genuine Microsoft authentication process. This surreptitious approach grants attackers access to the victim’s account, making the attack exceptionally difficult for average users to identify.

How the Device Code Phishing Attack Works

The Device Code flow is a standard Microsoft authentication mechanism designed for scenarios where traditional password entry is cumbersome, such as on smart TVs or command-line interfaces. Users are typically directed to a specific Microsoft URL and prompted to enter a short, device-specific code. This campaign weaponizes this helpful feature, transforming it into a trap to authorize an attacker-controlled device for account access.

Analysts at ReversingLabs have thoroughly documented this ongoing campaign. Their research highlights a combination of expertly crafted business-themed email lures, a sophisticated phishing kit, and the abuse of Microsoft’s Device Authorization Grant flow. This synergy enables what appears to be a routine Microsoft login, leading to a near-invisible account takeover.

According to a report by ReversingLabs researchers, shared with Cyber Security News (CSN), threat actors have refined this technique to bypass conventional security measures, making the malicious activity indistinguishable from a legitimate Microsoft login process.

The attack sequence typically begins with a phishing email, often disguised as an urgent approval request from a vendor or business associate. Clicking an embedded image in the email redirects the victim to a convincing fake landing page that meticulously mimics Microsoft’s official design. On this page, victims are instructed to copy a short code and then navigate to a genuine Microsoft device login page to enter it. At this stage, most users have no reason to suspect foul play, believing they are simply completing a standard authentication step.

Once the victim enters the code and completes their legitimate sign-in, Microsoft’s authentication system unknowingly authorizes the attacker’s device. The victim perceives no unusual activity, while the attacker simultaneously obtains a valid access token for the Microsoft 365 account. This token enables the attacker to access emails, files, and potentially move laterally within the victim’s organization.

Advanced Phishing Kit Evades Detection

The phishing kit underpinning this campaign is engineered for stealth and evasion. Its landing pages incorporate invisible Unicode characters, such as Zero Width Space, Word Joiner, and Zero Width Non-Joiner, strategically interspersed within words that security tools commonly flag as phishing indicators. This technique significantly complicates detection via traditional signature-based methods.

Further enhancing its legitimacy, the kit leverages Akamai’s infrastructure to host the device login entry point. The backend of the phishing kit also sends a POST request to the phishing host every four seconds, orchestrating the OAuth flow between the attacker and the victim’s authentication session. This consistent beacon is one of the few discernible network-level indicators of the ongoing attack.

Network traffic analysis can further aid in detection. Distinct clusters of hostname resolutions associated with the phishing landing page and the legitimate Microsoft authentication flow are identifiable. A third cluster comprises the beacon activity, occurring every four seconds after the initial authentication phase begins. This provides security teams with a reliable signal to search for within their network logs.

What You Should Do

  • Employee Training: Educate employees to be highly suspicious of any prompts asking them to copy and paste codes into a Microsoft login page, especially if the request comes unexpectedly.
  • Monitor Entra ID Logs: Regularly monitor Microsoft Entra ID (formerly Azure AD) sign-in logs for Device Code grant usage, particularly if the sign-in originates from an unknown or unusual endpoint (i.e., not a recognized IoT device or command-line tool).
  • Deploy Detections: Implement detections for the phishing kit artifacts detailed in the ReversingLabs report. This includes deploying the provided YARA rule for landing page identification and configuring network monitoring for the described traffic patterns.
  • Review IoCs: Integrate the provided Indicators of Compromise (IoCs) into your security information and event management (SIEM) systems, firewalls, and other security tools for proactive blocking and detection.

Indicators of Compromise (IoCs):-

Type Indicator Description
URL hxxp[://]ajz-gud[.]lisa-g-h-rn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]baquelite[.]ventoraco[.]com/doc98374/ Phishing kit landing page
URL hxxp[://]biotechgroup[.]p-oye8mc0f[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]bradhallfuel[.]p-oye8mc0f[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]corpexl[.]nl/mq5qh1xj9/ Phishing kit landing page
URL hxxp[://]corpexl[.]nl/oii/ Phishing kit landing page
URL hxxp[://]corpexl[.]nl/projectorder/ Phishing kit landing page
URL hxxp[://]creditora[.]me[.]uk/HPDGassocies Phishing kit landing page
URL hxxp[://]dentalstrategies[.]noventragroup[.]app/dntrategie/ Phishing kit landing page
URL hxxp[://]docxfile-share[.]itkljpqn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]docxfiletxz-share[.]itkljpqn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]gsbauwu1hsa[.]legalaro[.]com/nmasn/ Phishing kit landing page
URL hxxp[://]henriquevieira[.]horizoralabs[.]com/doc49390239/ Phishing kit landing page
URL hxxp[://]horizonex[.]it[.]com/confidentialrecord/ Phishing kit landing page
URL hxxp[://]horizonex[.]it[.]com/securedocument Phishing kit landing page
URL hxxp[://]hsecontractors-project[.]sign-ins[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]logvault[.]us/jfkydg4of/ Phishing kit landing page
URL hxxp[://]mcagroup[.]horizoralabs[.]com/quote937847/ Phishing kit landing page
URL hxxp[://]meeting[.]corpsfileshare[.]com/quarterly/ Phishing kit landing page
URL hxxp[://]metroraco[.]com/GroupeBergeron/ Phishing kit landing page
URL hxxp[://]metroraco[.]com/Vent/ Phishing kit landing page
URL hxxp[://]microsoft-document[.]adhere[.]it[.]com/Adobe-pdf/ Phishing kit landing page
URL hxxp[://]molinomerano[.]brieflync[.]nl/order9283/ Phishing kit landing page
URL hxxp[://]mysharereport[.]wgmilshyvn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]onedrive-document[.]adhere[.]it[.]com/sharedproject/ Phishing kit landing page
URL hxxp[://]retroactive[.]scalevantaco[.]com/adjustments Phishing kit landing page
URL hxxp[://]review[.]wgmilshyvn[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]sales[.]p-ct5v25xo[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]samoen[.]logvault[.]us/engineering Phishing kit landing page
URL hxxp[://]sparkaxis[.]org/deployment/ Phishing kit landing page
URL hxxp[://]tsk1[.]t31208026[.]workers[.]dev/ Phishing kit landing page
URL hxxp[://]uboralmaxillofacialsurgery[.]noventragroup[.]app/uboralxillofia Phishing kit landing page
URL hxxp[://]uegreil[.]taskvault[.]nl/itiwa2 Phishing kit landing page
URL hxxp[://]v379ge[.]meetrova[.]nl/p9mxbmz2x/ Phishing kit landing page
URL hxxp[://]wpdoi8w[.]elevatecore[.]it[.]com/g4jlitpi/ Phishing kit landing page
URL hxxp[://]wylderhotels[.]sparkaxis[.]org/personaljflannigan/ Phishing kit landing page
URL hxxp[://]zktxnxlh[.]stratavaco[.]com/snzv8wq Phishing kit landing page
URL hxxps[://]adhere[.]it[.]com/verify/ Phishing kit landing page
URL hxxps[://]apexviaco[.]com/code/ Phishing kit landing page
URL hxxps[://]corpexl[.]nl/INV/ Phishing kit landing page
URL hxxps[://]corpexl[.]nl/PO/ Phishing kit landing page
URL hxxps[://]corpexl[.]nl/securee/ Phishing kit landing page
URL hxxps[://]covenant[.]it[.]com/Project/ Phishing kit landing page
URL hxxps[://]creditora[.]me[.]uk/NorthShore/ Phishing kit landing page
URL hxxps[://]docusign-arizonacreativeevents[.]nextvexharbor[.]de/review/ Phishing kit landing page
URL hxxps[://]docusign-stlequityhomes[.]nextvexharbor[.]de/review/ Phishing kit landing page
URL hxxps[://]fortknox[.]noventragroup[.]app/fortknoxxx/ Phishing kit landing page
URL hxxps[://]growthora[.]app/doc/ Phishing kit landing page
URL hxxps[://]horizonex[.]it[.]com/confidentialfile/ Phishing kit landing page
URL hxxps[://]login[.]growthora[.]app/document/ Phishing kit landing page
URL hxxps[://]meeting[.]corpsfileshare[.]com/quarterly/ Phishing kit landing page
URL hxxps[://]metroraco[.]com/Desjardinsh/ Phishing kit landing page
URL hxxps[://]metroraco[.]com/InnovativePipeline/ Phishing kit landing page
URL hxxps[://]momentoraco[.]com/Project-submittal/ Phishing kit landing page
URL hxxps[://]momentoraco[.]com/project-document/ Phishing kit landing page
URL hxxps[://]my-team-share[.]corpsfileshare[.]com/team/ Phishing kit landing page
URL hxxps[://]nexttrail[.]co[.]nl/m365scoft/ Phishing kit landing page
URL hxxps[://]onedrive-encrypted-online[.]clearledge[.]me[.]uk/avc8xt/ Phishing kit landing page
URL hxxps[://]onedrive-encrypted[.]clearledge[.]me[.]uk/aar0cphl/ Phishing kit landing page
URL hxxps[://]onedrive-microsoft[.]adhere[.]it[.]com/securedocument/ Phishing kit landing page
URL hxxps[://]payroll[.]vardeno[.]nl/employee/ Phishing kit landing page
URL hxxps[://]ringcentral[.]firmtix[.]com/alert/ Phishing kit landing page
URL hxxps[://]ringcentral[.]firmtix[.]com/notify/ Phishing kit landing page
URL hxxps[://]secure[.]firmtix[.]com/docx Phishing kit landing page
URL hxxps[://]sparkaxis[.]org/delivery/ Phishing kit landing page
URL hxxps[://]sparkaxis[.]org/statement/ Phishing kit landing page
URL hxxps[://]stratifylabs[.]org/BDAGroup/ Phishing kit landing page
URL hxxps[://]stratifylabs[.]org/FACTURE/ Phishing kit landing page
URL hxxps[://]teams[.]vardeno[.]nl/fileshared/ Phishing kit landing page
URL hxxps[://]trenix[.]nl/alma-resort/ Phishing kit landing page
URL hxxps[://]verif[.]futureanchor[.]it[.]com/cloud/ Phishing kit landing page
URL hxxps[://]verification[.]futureanchor[.]it[.]com/cardcrosoft/ Phishing kit landing page
URL hxxps[://]vmservfill[.]nkydzvws[.]workers[.]dev/ Phishing kit landing page
Network Hostname login.microsoftonline.com Legitimate Microsoft authentication endpoint abused in Device Code flow
Network Hostname aka.ms/devicelogin Legitimate Microsoft device login URL referenced in phishing lures
Network Hostname login.live.com/oauth20_remoteconnect.srf Legitimate Microsoft Live auth endpoint abused in phishing kit
YARA Rule DeviceCode_Phishing_LandingPageHTML YARA detection rule for Device Code phishing kit landing pages (authored by Malware Utkonos, dated 2026-05-20)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Microsoft Teams Flaw Lets Attackers Hide Malware Traffic

Next Post

India Bans Telegram Messenger Over Medical Exam Fraud

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Critical SonicWall SMA 1000 Zero-Days Exploited in Ransomware Attacks
August 11, 2026
Critical VMware vCenter CVE-2023-34048 Under Active Exploitation
August 11, 2026
Critical ClamAV Vulnerabilities Let Attackers Trigger DoS
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us