ZeroHour
Threat actor

GhostCode

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

GhostCode phishing kit abuses Microsoft's OAuth device authorization flow to harvest tokens, register devices, and steal primary refresh tokens from M365 victims.

eSentire's threat response unit identified in late August 2026 a campaign using the GhostCode kit, which abuses Microsoft's OAuth 2.0 device authorization grant flow: attackers posing as procurement officers lure victims to an NDA-themed HTML file that leads to a device-code phishing page where victims complete MFA for attacker-generated codes. Automated post-authentication activity registered three attacker devices within 78 seconds, enrolled one in Microsoft Intune with enrollment surviving token revocation, and obtained a Primary Refresh Token granting SSO-equivalent M365 access for up to 14 days. eSentire advises restricting device-code authentication via Conditional Access, auditing Entra ID device registrations, and monitoring python-requests user agents after device-code sign-ins.

CSO Online · 2h agoPhishing & fraud in the wild 3 sources1

GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation

eSentire exposes GhostCode, a device-code phishing kit that abuses Microsoft Entra device enrollment to persist even after stolen tokens are revoked.

eSentire's Threat Response Unit observed GhostCode campaigns in late August 2026, using BEC-style social engineering that impersonated procurement staff, including BJ's Wholesale Club, via Salesforce contact forms. Victims received password-protected HTML lures disguised as a FlipBook document portal, with junk-data padding, HTML comment injection, and AES-256-GCM encrypted redirects gated by anti-bot checks. The kit exploits the OAuth 2.0 device authorization grant, prompting victims to approve real Microsoft device-code sign-ins with MFA. Within 78 seconds of approval, attackers registered three Entra devices and obtained a Primary Refresh Token, so rogue device registrations persist even after session token revocation.

GBHackersupdated · 2h agofirst · 2d agoPhishing & fraud in the wild 3 sources3