Researchers and incident responders are warning that attackers are increasingly abusing Microsoft Entra ID's OAuth 2.0 device code flow to hijack Microsoft 365 accounts through legitimate sign-in prompts rather than malware or software exploits. In these attacks, victims are tricked via vishing or phishing into entering an attacker-supplied code at Microsoft's device login page and approving MFA, which issues the attacker valid access and refresh tokens. Security firms say the technique can provide broad access to services including Microsoft Graph, Exchange Online, OneDrive, and SharePoint, and that password resets alone may not fully contain the intrusion because refresh tokens can persist across services.
The activity has been tied to data theft and follow-on abuse. ReliaQuest reported that the Helix extortion group used device code phishing, MFA abuse, and rogue authenticator registration to access victim Microsoft 365 tenants, enumerate SharePoint, and exfiltrate data before extortion; reported victims include Medtronic, Nissan, NAIC, Kodak, Infinite Campus, and the University of Nottingham. Separate investigations documented attackers signing in from foreign locations, registering multiple devices, creating hidden inbox rules to suppress replies, and using compromised mailboxes to send phishing messages at scale. Microsoft and security researchers recommend blocking or restricting device code authentication with Conditional Access, limiting SharePoint and device registration to managed devices, and monitoring Entra ID telemetry for AuthenticationProtocol set to device code, unusual travel, mailbox rule changes, and spikes in device registrations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Gurucul described Kali365 as a high-severity phishing-as-a-service kit targeting U.S. organizations through Microsoft device code phishing, enabling attackers to obtain OAuth access and refresh tokens for persistent Microsoft 365 access. The report also published associated domains and URLs and provided detection queries for identifying related activity.
Trend Micro reported on an investigated device-code phishing case in which an attacker gained cloud account access, later signed in from abroad, registered multiple devices, created a hidden inbox rule, and used the compromised mailbox to send phishing emails to hundreds of external recipients. The report provided identity-focused detection guidance and recommended disabling device-code flow where unnecessary.
Researchers identified a new data extortion group called Helix that steals Microsoft 365 access through social engineering methods including vishing, device code phishing, and MFA abuse rather than software exploitation. Reported victims included Medtronic, Nissan, NAIC, Kodak, Infinite Campus, and the University of Nottingham, with activity focused on SharePoint data theft and extortion.
TrustedSec published an analysis of how attackers abuse Microsoft Entra ID's OAuth 2.0 device code flow to phish users into approving legitimate sign-ins, yielding access and refresh tokens for Microsoft 365 services. The article also highlighted detection opportunities in Entra ID logs and recommended blocking device code flow with Conditional Access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcetrendmicro.com
Open sourcecommunity.gurucul.com
Open sourcecysecurity.news
Open sourcetrustedsec.com
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.