GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
eSentire identified GhostCode, a phishing kit abusing Microsoft 365 OAuth device-code sign-in to steal tokens and take over accounts in seconds.
eSentire analysts identified GhostCode in late August, a phishing kit that uses business contact-form messages and an NDA pretext to deliver a password-protected HTML attachment leading victims to a Microsoft device-code sign-in. Victims authenticate on legitimate Microsoft pages, letting the kit obtain a Primary Refresh Token in 32 seconds and register three devices in 78 seconds, with residential proxies matching the victim's location. The kit hides its redirect with encrypted addresses, junk data, and scanner-filtering challenges, and uses GHOSTnet-linked infrastructure during device enrolment. eSentire recommends blocking device-code authentication via Conditional Access, invalidating tokens, and reviewing newly enrolled devices.
- Abuses OAuth device authorization via the Microsoft Authentication Broker application ID
- Password-protected HTML attachment hides its encrypted redirect until the password is entered
- Primary Refresh Token harvested in 32 seconds; three devices registered in 78 seconds
- Residential proxies matching victim location weaken location-based Microsoft alerts
- Enrolled devices persist until admins explicitly disable or remove them
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | bjssourcing.com | rs of Compromise (IoCs):- Type Indicator Description Domain bjssourcing[.]com Lookalike sender domain used in the procurement-officer p |
| domain | elitechiropracticandrehab.com | crypted redirect destination Domain account-access-rc3uenqi.elitechiropracticandrehab[.]com Device-code phishing server hosted under a likely comprom |
| domain | flipbookonlinevault.com | ent used as the document-sharing lure URL hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa14 |
| domain | greenlightdlstribution.com | ender domain used in the procurement-officer pretext Domain greenlightdlstribution[.]com Related impersonation domain registered during the campai |
| domain | voewo.com | tered during the campaign period Email address jeremyarcher@voewo[.]com Disposable address associated with registration of a rela |
| md5 | 200e61bfe54c92fb720c77c3a1661bc0 | lure URL hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d |
| sha256 | b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d106d7 | okonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d106d7 Decrypted relay URL used for tracking, filtering, and redir |
| url | https://chartered.flipbookonlinevault[ | ected HTML attachment used as the document-sharing lure URL hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3a |
Full article1,050 words · extracted from cybersecuritynews.com · click to collapse
GhostCode is a newly identified phishing kit that turns a normal Microsoft 365 sign-in into an account takeover. It does not need to steal a password. Instead, it persuades people to approve a login that gives criminals access to their work account.
The campaign began with ordinary-looking messages submitted through business contact forms. Attackers posed as procurement staff, followed up with a request to sign a non-disclosure agreement, then sent a WeTransfer link holding a password-protected HTML attachment.
The file presented a document-sharing lure and directed the recipient to a Microsoft device-code sign-in. Analysts at eSentire identified the activity in late August and named the kit GhostCode. The name reflects its hidden code and the use of GHOSTnet-linked infrastructure during device enrolment.
eSentire said in a report shared with Cyber Security News (CSN) that the operation used a business-email-compromise style pretext to make the request appear routine.
The risk is immediate because the victim completes authentication, including multi-factor authentication, on a legitimate Microsoft page.
GhostCode then receives the resulting token, sends the victim to a decoy NDA, and begins operating before the victim has reason to suspect a problem. The case underlines why device code phishing campaigns are difficult to spot using familiar password-theft warning signs.
.webp)
The campaign shows how trust in a familiar identity page, rather than a technical flaw, can become the attacker’s advantage. For cloud-dependent organisations, that distinction turns a routine approval request into a serious account-security event. It can unfold before investigators review the first alert.
GhostCode Phishing Kit Bypasses Microsoft 365 MFA
GhostCode abuses the OAuth device authorization process, which is intended for devices such as smart televisions that cannot easily display a full sign-in screen.
Its server requests a code using the Microsoft Authentication Broker application ID, inserts that code into a polished fake document portal, and asks the target to authenticate it. The user is effectively authorising the attacker’s device.
The attachment makes inspection harder. It is padded with junk data, breaks visible text with HTML comments, and keeps its redirect address encrypted until the correct password is supplied.
After the victim reaches the phishing server, a browser challenge and location checks filter automated scanners. This approach resembles techniques previously documented in the EvilTokens phishing service, but GhostCode combines them with targeted contact-form outreach.
.webp)
Once the sign-in is approved, the kit uses residential proxy addresses selected to match the victim’s location. That makes the Microsoft prompt less alarming and can weaken location-based alerts.
In the observed intrusion, attackers made nine successful API calls, registered three devices in 78 seconds, and obtained a Primary Refresh Token in 32 seconds. That token can support sign-on across Microsoft 365 services without asking the user to authenticate again.
Containing a Fast-Moving Identity Attack
Speed matters because simply revoking a stolen token may not remove devices already registered in the tenant. The researchers found that enrolled devices remain until administrators explicitly disable or remove them.
Teams responding to suspicious device-code activity should invalidate tokens, reset affected credentials, review newly enrolled devices, and check mail and cloud-access logs for follow-on activity.
The recommended control is to block device-code authentication through Conditional Access for everyone who does not genuinely need it, while allowing tightly defined exceptions for approved service or provisioning workflows.
.webp)
Organisations should also apply device-compliance controls where suitable. This reduces the number of employees who could be tricked by the same method used in passkey-themed phishing attacks.
Security teams should alert on successful device-code events followed by anomalous scripted requests or several device registrations from one non-interactive session. They should also hunt for device names matching a first-name, last-name, company-domain and hexadecimal suffix pattern.
User awareness remains important: an unexpected request to copy a code into a Microsoft page should be treated as suspicious, particularly as Microsoft 365 session theft campaigns continue to focus on tokens rather than passwords.
Indicators of Compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/ghostcode-phishing-kit/