GhostCode Phishing Kit Abuses Microsoft Entra Device Enrollment to Keep Access After Token Revocation
eSentire's Threat Response Unit exposed GhostCode, a device-code phishing kit that abuses the Microsoft 365 OAuth device authorization grant to hijack MFA-protected accounts and persist via Primary Refresh Tokens and rogue Entra device enrollments even after…
eSentire's Threat Response Unit observed GhostCode campaigns in late August 2026. The kit uses BEC-style social engineering delivered through business contact forms — including messages impersonating BJ's Wholesale Club procurement staff sent via Salesforce contact forms, with an NDA pretext — to push victims toward password-protected HTML lures disguised as a FlipBook document portal. The lures employ junk-data padding, HTML comment injection, and redirects encrypted with PBKDF2-derived AES-256-GCM, hidden behind anti-bot and scanner-filtering challenges so the phishing URL stays concealed until the password is entered. Victims are then prompted to approve a genuine Microsoft device-code sign-in (OAuth 2.0 device authorization grant, via the Microsoft Authentication Broker application ID) with MFA. After approval, attackers connect through residential proxies matching the victim's location and use GHOSTnet-linked infrastructure during device enrollment to harvest a Primary Refresh Token and register three rogue Entra devices. The two reports disagree slightly on timing: GBHackers says both the Primary Refresh Token and the three device registrations occur within 78 seconds of approval, while Cyber Security News reports the token is harvested in 32 seconds and the three devices registered in 78 seconds. The rogue Intune/Entra enrollments persist even after session tokens are revoked, remaining active until admins explicitly disable or remove the devices. eSentire also noted more than 30 lookalike mail-enabled domains registered for BEC staging, and recommends blocking device-code authentication via Conditional Access, invalidating tokens, and reviewing newly enrolled devices.
- Attribution/observer: eSentire's Threat Response Unit identified GhostCode campaigns in late August 2026; both reports published 2026-09-16.
- Initial access: BEC-style social engineering via business/Salesforce contact forms, impersonating procurement staff including BJ's Wholesale Club, using an NDA pretext.
- Lure delivery: password-protected HTML attachment disguised as a FlipBook document portal, with junk-data padding, HTML comment injection, and anti-bot/scanner-filtering challenges.
- Obfuscation: phishing redirect encrypted with PBKDF2-derived AES-256-GCM and hidden until the password is entered.
- Technique: abuses the OAuth 2.0 device authorization grant via the Microsoft Authentication Broker application ID; victims approve real Microsoft device-code sign-ins with MFA.
- Timing (sources differ): GBHackers states the Primary Refresh Token and three Entra device registrations both occur within 78 seconds of approval; Cyber Security News states the Primary Refresh Token is harvested in 32 seconds and the…
- Persistence: rogue Entra/Intune device enrollments with Primary Refresh Tokens survive session token revocation and remain until admins explicitly disable or remove them.
- Infrastructure: over 30 lookalike mail-enabled domains registered for BEC staging; residential proxies matching the victim's location weaken location-based Microsoft alerts; GHOSTnet-linked infrastructure used during device enrollment.
Coverage timelineoldest first · each row is one article
- · 11h agoGhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation
GBHackers· 73
eSentire exposes GhostCode, a device-code phishing kit that abuses Microsoft Entra device enrollment to persist even after stolen tokens are revoked.