ZeroHour
Organization

eSentire

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

GhostCode phishing kit abuses Microsoft's OAuth device authorization flow to harvest tokens, register devices, and steal primary refresh tokens from M365 victims.

eSentire's threat response unit identified in late August 2026 a campaign using the GhostCode kit, which abuses Microsoft's OAuth 2.0 device authorization grant flow: attackers posing as procurement officers lure victims to an NDA-themed HTML file that leads to a device-code phishing page where victims complete MFA for attacker-generated codes. Automated post-authentication activity registered three attacker devices within 78 seconds, enrolled one in Microsoft Intune with enrollment surviving token revocation, and obtained a Primary Refresh Token granting SSO-equivalent M365 access for up to 14 days. eSentire advises restricting device-code authentication via Conditional Access, auditing Entra ID device registrations, and monitoring python-requests user agents after device-code sign-ins.

CSO Online · 2h agoPhishing & fraud in the wild 3 sources1

GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds

eSentire identified GhostCode, a phishing kit abusing Microsoft 365 OAuth device-code sign-in to steal tokens and take over accounts in seconds.

eSentire analysts identified GhostCode in late August, a phishing kit that uses business contact-form messages and an NDA pretext to deliver a password-protected HTML attachment leading victims to a Microsoft device-code sign-in. Victims authenticate on legitimate Microsoft pages, letting the kit obtain a Primary Refresh Token in 32 seconds and register three devices in 78 seconds, with residential proxies matching the victim's location. The kit hides its redirect with encrypted addresses, junk data, and scanner-filtering challenges, and uses GHOSTnet-linked infrastructure during device enrolment. eSentire recommends blocking device-code authentication via Conditional Access, invalidating tokens, and reviewing newly enrolled devices.

Cyber Security Newsupdated · 2h agofirst · 2d agoPhishing & fraud in the wild 3 sources5

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.