GhostCode attackers abuse device codes to take over Microsoft 365 accounts
GhostCode phishing kit abuses Microsoft's OAuth device authorization flow to harvest tokens, register devices, and steal primary refresh tokens from M365 victims.
eSentire's threat response unit identified in late August 2026 a campaign using the GhostCode kit, which abuses Microsoft's OAuth 2.0 device authorization grant flow: attackers posing as procurement officers lure victims to an NDA-themed HTML file that leads to a device-code phishing page where victims complete MFA for attacker-generated codes. Automated post-authentication activity registered three attacker devices within 78 seconds, enrolled one in Microsoft Intune with enrollment surviving token revocation, and obtained a Primary Refresh Token granting SSO-equivalent M365 access for up to 14 days. eSentire advises restricting device-code authentication via Conditional Access, auditing Entra ID device registrations, and monitoring python-requests user agents after device-code sign-ins.