Ghost Hub is a phishing-as-a-service kit associated with Microsoft device code phishing operations targeting Microsoft 365 users. It is part of a broader ecosystem of commodity phishing services that operationalize abuse of Microsoft’s legitimate OAuth device authorization flow to obtain access and refresh tokens after a victim completes authentication. This enables persistent access to Microsoft 365 resources without directly capturing the victim’s password. Ghost Hub has been observed in campaigns that used trusted third-party infrastructure and legitimate service workflows to increase credibility and evade detection. Documented activity included abuse of legitimate Adobe Acrobat document-sharing mechanisms and Adobe-hosted redirect infrastructure before presenting a Microsoft-themed device code lure. As with other device code phishing operations, successful compromise can support follow-on reconnaissance, phishing from compromised accounts, data theft, and business email compromise. Ghost Hub appears in the same active device code phishing ecosystem as EvilTokens, Kali365, Cyb3r, and Tycoon2FA. High-confidence reporting supports Ghost Hub’s role as a phishing kit rather than a clearly attributed nation-state or geographically assigned intrusion set. Its observed tradecraft aligns with initial access operations, session abuse through token theft, persistence via refresh tokens, reconnaissance, and exfiltration-oriented post-compromise activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.