Microsoft 365 Device Code Phishing Bypasses MFA for Account Takeover
Key Takeaways A sophisticated phishing campaign is actively targeting Microsoft 365 users. The attack exploits Microsoft’s legitimate Device Code authentication flow, bypassing traditional MFA...
Key Takeaways
- A sophisticated phishing campaign is actively targeting Microsoft 365 users.
- The attack exploits Microsoft’s legitimate Device Code authentication flow, bypassing traditional MFA protections.
- Threat actors gain full account control without ever stealing a password, making detection difficult for users.
- Security researchers have identified unique indicators of compromise (IoCs), including specific network traffic patterns and a YARA rule for detection.
Microsoft 365 Device Code Phishing Campaign Bypasses MFA
A new, highly effective phishing campaign has emerged, targeting Microsoft 365 users by exploiting a legitimate authentication feature to gain unauthorized account access. This method, termed Device Code phishing, represents a significant evolution from typical password-stealing attacks, as it allows attackers to bypass multi-factor authentication (MFA) and seize control of accounts without ever directly asking for user credentials.
Table Of Content
Instead of attempting to trick users into divulging their passwords on a fake login page, this campaign manipulates victims into unknowingly completing a genuine Microsoft authentication process. This surreptitious approach grants attackers access to the victim’s account, making the attack exceptionally difficult for average users to identify.
How the Device Code Phishing Attack Works
The Device Code flow is a standard Microsoft authentication mechanism designed for scenarios where traditional password entry is cumbersome, such as on smart TVs or command-line interfaces. Users are typically directed to a specific Microsoft URL and prompted to enter a short, device-specific code. This campaign weaponizes this helpful feature, transforming it into a trap to authorize an attacker-controlled device for account access.
Analysts at ReversingLabs have thoroughly documented this ongoing campaign. Their research highlights a combination of expertly crafted business-themed email lures, a sophisticated phishing kit, and the abuse of Microsoft’s Device Authorization Grant flow. This synergy enables what appears to be a routine Microsoft login, leading to a near-invisible account takeover.
According to a report by ReversingLabs researchers, shared with Cyber Security News (CSN), threat actors have refined this technique to bypass conventional security measures, making the malicious activity indistinguishable from a legitimate Microsoft login process.
The attack sequence typically begins with a phishing email, often disguised as an urgent approval request from a vendor or business associate. Clicking an embedded image in the email redirects the victim to a convincing fake landing page that meticulously mimics Microsoft’s official design. On this page, victims are instructed to copy a short code and then navigate to a genuine Microsoft device login page to enter it. At this stage, most users have no reason to suspect foul play, believing they are simply completing a standard authentication step.
Once the victim enters the code and completes their legitimate sign-in, Microsoft’s authentication system unknowingly authorizes the attacker’s device. The victim perceives no unusual activity, while the attacker simultaneously obtains a valid access token for the Microsoft 365 account. This token enables the attacker to access emails, files, and potentially move laterally within the victim’s organization.
Advanced Phishing Kit Evades Detection
The phishing kit underpinning this campaign is engineered for stealth and evasion. Its landing pages incorporate invisible Unicode characters, such as Zero Width Space, Word Joiner, and Zero Width Non-Joiner, strategically interspersed within words that security tools commonly flag as phishing indicators. This technique significantly complicates detection via traditional signature-based methods.
Further enhancing its legitimacy, the kit leverages Akamai’s infrastructure to host the device login entry point. The backend of the phishing kit also sends a POST request to the phishing host every four seconds, orchestrating the OAuth flow between the attacker and the victim’s authentication session. This consistent beacon is one of the few discernible network-level indicators of the ongoing attack.
Network traffic analysis can further aid in detection. Distinct clusters of hostname resolutions associated with the phishing landing page and the legitimate Microsoft authentication flow are identifiable. A third cluster comprises the beacon activity, occurring every four seconds after the initial authentication phase begins. This provides security teams with a reliable signal to search for within their network logs.
What You Should Do
- Employee Training: Educate employees to be highly suspicious of any prompts asking them to copy and paste codes into a Microsoft login page, especially if the request comes unexpectedly.
- Monitor Entra ID Logs: Regularly monitor Microsoft Entra ID (formerly Azure AD) sign-in logs for Device Code grant usage, particularly if the sign-in originates from an unknown or unusual endpoint (i.e., not a recognized IoT device or command-line tool).
- Deploy Detections: Implement detections for the phishing kit artifacts detailed in the ReversingLabs report. This includes deploying the provided YARA rule for landing page identification and configuring network monitoring for the described traffic patterns.
- Review IoCs: Integrate the provided Indicators of Compromise (IoCs) into your security information and event management (SIEM) systems, firewalls, and other security tools for proactive blocking and detection.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxp[://]ajz-gud[.]lisa-g-h-rn[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]baquelite[.]ventoraco[.]com/doc98374/ | Phishing kit landing page |
| URL | hxxp[://]biotechgroup[.]p-oye8mc0f[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]bradhallfuel[.]p-oye8mc0f[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]corpexl[.]nl/mq5qh1xj9/ | Phishing kit landing page |
| URL | hxxp[://]corpexl[.]nl/oii/ | Phishing kit landing page |
| URL | hxxp[://]corpexl[.]nl/projectorder/ | Phishing kit landing page |
| URL | hxxp[://]creditora[.]me[.]uk/HPDGassocies | Phishing kit landing page |
| URL | hxxp[://]dentalstrategies[.]noventragroup[.]app/dntrategie/ | Phishing kit landing page |
| URL | hxxp[://]docxfile-share[.]itkljpqn[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]docxfiletxz-share[.]itkljpqn[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]gsbauwu1hsa[.]legalaro[.]com/nmasn/ | Phishing kit landing page |
| URL | hxxp[://]henriquevieira[.]horizoralabs[.]com/doc49390239/ | Phishing kit landing page |
| URL | hxxp[://]horizonex[.]it[.]com/confidentialrecord/ | Phishing kit landing page |
| URL | hxxp[://]horizonex[.]it[.]com/securedocument | Phishing kit landing page |
| URL | hxxp[://]hsecontractors-project[.]sign-ins[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]logvault[.]us/jfkydg4of/ | Phishing kit landing page |
| URL | hxxp[://]mcagroup[.]horizoralabs[.]com/quote937847/ | Phishing kit landing page |
| URL | hxxp[://]meeting[.]corpsfileshare[.]com/quarterly/ | Phishing kit landing page |
| URL | hxxp[://]metroraco[.]com/GroupeBergeron/ | Phishing kit landing page |
| URL | hxxp[://]metroraco[.]com/Vent/ | Phishing kit landing page |
| URL | hxxp[://]microsoft-document[.]adhere[.]it[.]com/Adobe-pdf/ | Phishing kit landing page |
| URL | hxxp[://]molinomerano[.]brieflync[.]nl/order9283/ | Phishing kit landing page |
| URL | hxxp[://]mysharereport[.]wgmilshyvn[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]onedrive-document[.]adhere[.]it[.]com/sharedproject/ | Phishing kit landing page |
| URL | hxxp[://]retroactive[.]scalevantaco[.]com/adjustments | Phishing kit landing page |
| URL | hxxp[://]review[.]wgmilshyvn[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]sales[.]p-ct5v25xo[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]samoen[.]logvault[.]us/engineering | Phishing kit landing page |
| URL | hxxp[://]sparkaxis[.]org/deployment/ | Phishing kit landing page |
| URL | hxxp[://]tsk1[.]t31208026[.]workers[.]dev/ | Phishing kit landing page |
| URL | hxxp[://]uboralmaxillofacialsurgery[.]noventragroup[.]app/uboralxillofia | Phishing kit landing page |
| URL | hxxp[://]uegreil[.]taskvault[.]nl/itiwa2 | Phishing kit landing page |
| URL | hxxp[://]v379ge[.]meetrova[.]nl/p9mxbmz2x/ | Phishing kit landing page |
| URL | hxxp[://]wpdoi8w[.]elevatecore[.]it[.]com/g4jlitpi/ | Phishing kit landing page |
| URL | hxxp[://]wylderhotels[.]sparkaxis[.]org/personaljflannigan/ | Phishing kit landing page |
| URL | hxxp[://]zktxnxlh[.]stratavaco[.]com/snzv8wq | Phishing kit landing page |
| URL | hxxps[://]adhere[.]it[.]com/verify/ | Phishing kit landing page |
| URL | hxxps[://]apexviaco[.]com/code/ | Phishing kit landing page |
| URL | hxxps[://]corpexl[.]nl/INV/ | Phishing kit landing page |
| URL | hxxps[://]corpexl[.]nl/PO/ | Phishing kit landing page |
| URL | hxxps[://]corpexl[.]nl/securee/ | Phishing kit landing page |
| URL | hxxps[://]covenant[.]it[.]com/Project/ | Phishing kit landing page |
| URL | hxxps[://]creditora[.]me[.]uk/NorthShore/ | Phishing kit landing page |
| URL | hxxps[://]docusign-arizonacreativeevents[.]nextvexharbor[.]de/review/ | Phishing kit landing page |
| URL | hxxps[://]docusign-stlequityhomes[.]nextvexharbor[.]de/review/ | Phishing kit landing page |
| URL | hxxps[://]fortknox[.]noventragroup[.]app/fortknoxxx/ | Phishing kit landing page |
| URL | hxxps[://]growthora[.]app/doc/ | Phishing kit landing page |
| URL | hxxps[://]horizonex[.]it[.]com/confidentialfile/ | Phishing kit landing page |
| URL | hxxps[://]login[.]growthora[.]app/document/ | Phishing kit landing page |
| URL | hxxps[://]meeting[.]corpsfileshare[.]com/quarterly/ | Phishing kit landing page |
| URL | hxxps[://]metroraco[.]com/Desjardinsh/ | Phishing kit landing page |
| URL | hxxps[://]metroraco[.]com/InnovativePipeline/ | Phishing kit landing page |
| URL | hxxps[://]momentoraco[.]com/Project-submittal/ | Phishing kit landing page |
| URL | hxxps[://]momentoraco[.]com/project-document/ | Phishing kit landing page |
| URL | hxxps[://]my-team-share[.]corpsfileshare[.]com/team/ | Phishing kit landing page |
| URL | hxxps[://]nexttrail[.]co[.]nl/m365scoft/ | Phishing kit landing page |
| URL | hxxps[://]onedrive-encrypted-online[.]clearledge[.]me[.]uk/avc8xt/ | Phishing kit landing page |
| URL | hxxps[://]onedrive-encrypted[.]clearledge[.]me[.]uk/aar0cphl/ | Phishing kit landing page |
| URL | hxxps[://]onedrive-microsoft[.]adhere[.]it[.]com/securedocument/ | Phishing kit landing page |
| URL | hxxps[://]payroll[.]vardeno[.]nl/employee/ | Phishing kit landing page |
| URL | hxxps[://]ringcentral[.]firmtix[.]com/alert/ | Phishing kit landing page |
| URL | hxxps[://]ringcentral[.]firmtix[.]com/notify/ | Phishing kit landing page |
| URL | hxxps[://]secure[.]firmtix[.]com/docx | Phishing kit landing page |
| URL | hxxps[://]sparkaxis[.]org/delivery/ | Phishing kit landing page |
| URL | hxxps[://]sparkaxis[.]org/statement/ | Phishing kit landing page |
| URL | hxxps[://]stratifylabs[.]org/BDAGroup/ | Phishing kit landing page |
| URL | hxxps[://]stratifylabs[.]org/FACTURE/ | Phishing kit landing page |
| URL | hxxps[://]teams[.]vardeno[.]nl/fileshared/ | Phishing kit landing page |
| URL | hxxps[://]trenix[.]nl/alma-resort/ | Phishing kit landing page |
| URL | hxxps[://]verif[.]futureanchor[.]it[.]com/cloud/ | Phishing kit landing page |
| URL | hxxps[://]verification[.]futureanchor[.]it[.]com/cardcrosoft/ | Phishing kit landing page |
| URL | hxxps[://]vmservfill[.]nkydzvws[.]workers[.]dev/ | Phishing kit landing page |
| Network Hostname | login.microsoftonline.com | Legitimate Microsoft authentication endpoint abused in Device Code flow |
| Network Hostname | aka.ms/devicelogin | Legitimate Microsoft device login URL referenced in phishing lures |
| Network Hostname | login.live.com/oauth20_remoteconnect.srf | Legitimate Microsoft Live auth endpoint abused in phishing kit |
| YARA Rule | DeviceCode_Phishing_LandingPageHTML | YARA detection rule for Device Code phishing kit landing pages (authored by Malware Utkonos, dated 2026-05-20) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.