Five Nights At Freddys 4

Survive The Night Again

Breaking News
Jump Scares

Hackers hijack Microsoft 365 accounts via device-code phishing

By Dewi Santoso September 19, 2026
Hackers hijack Microsoft 365 accounts via device-code phishing - microsoft 365 phishing
The stolen tokens enable deep persistence in the victim’s Microsoft environment.

A new phishing campaign called GhostCode is exploiting a legitimate Microsoft authentication method to hijack Microsoft 365 accounts, researchers say. The attack targets the OAuth 2.0 device authorization flow, a system designed for devices like smart TVs or printers that can’t use standard browser logins. Instead of requiring a password, the process generates a code displayed on the device, which users then enter on another device to complete authentication.

GhostCode mimics this flow, tricking victims into entering a device code on Microsoft’s login page. Once entered, the attacker-controlled device captures the authentication tokens, allowing them to register additional devices and maintain access. The campaign observed by eSentire’s threat response team in late August 2026 began with attackers posing as procurement officers through a web contact form, then directing victims to an NDA-themed HTML file that led to the phishing page.

The stolen tokens enable deep persistence in the victim’s Microsoft environment. Within 78 seconds of authentication, eSentire recorded nine API calls targeting Microsoft Intune Enrollment, the Device Registration Service, Azure Active Directory, and Microsoft Graph. Three attacker-controlled devices were registered at intervals of 28, 53, and 77 seconds, a sequence the researchers described as automated.

The third device was successfully enrolled in Intune, Microsoft’s cloud-based device management service, and remained in the tenant even after token revocation. The attackers also obtained a Primary Refresh Token (PRT), one of the most powerful credentials in a Microsoft identity environment. A PRT provides SSO-equivalent access to the victim’s entire M365 environment for up to 14 days, unless blocked by a Conditional Access policy requiring a compliant device.

To evade detection, the attackers used multiple techniques, including padding and obfuscating the HTML code in their lure, encrypting redirects, and employing Cloudflare Turnstile to block security tools from accessing the phishing page. They also checked for automated bots to avoid automated scans.

Defending against GhostCode requires restricting Microsoft’s device-code authentication flow through Conditional Access and disabling it for users who don’t need it. Organizations should also monitor the Device Registration Service for unusual activity, such as multiple device registrations from a single non-interactive session. Detecting python-requests activity following device-code authentication could help catch attacks in progress.

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 Five Nights At Freddys 4. All rights reserved.