Attackers are exploiting Microsoft Entra ID's Device Registration Service after compromising user identities—often through device-code phishing—to enroll attacker-controlled devices in victim tenants. The rogue devices can satisfy Conditional Access requirements, provide persistence, and enable subsequent access to Microsoft 365 data, email exfiltration, and wider tenant activity. Open-source tooling such as ROADtools can support Entra ID reconnaissance and cloud-account abuse, while attackers increasingly vary device metadata to evade detections tied to known tooling artifacts.
Static indicators including the Dsreg/10.0 User-Agent and DESKTOP-XXXXXXXX device names are becoming less reliable as operators use generic, customized, or AI-generated identifiers. Organizations should detect anomalous device registrations behaviorally, correlate device-code phishing activity with new device joins, and compare device names and registration patterns against tenant baselines. MFA for registration, network-based restrictions, and Conditional Access policies requiring compliant devices can reduce this attack path.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Attackers were observed moving beyond recognizable ROADrecon artifacts such as the Dsreg/10.0 user agent and DESKTOP-XXXXXXXX device names, including minor naming variations and a device named "Work PC" registered with the MSTokens-PRT/1.0 user agent. This reduced the reliability of static device-name and user-agent detections.
Researchers observed a shared-document-lure phishing page at lockwall.xyz/prime/ presenting a pre-generated Microsoft device code, with activity linked to AWS IP address 3.149.231.11 across multiple victims. The phishing activity enabled a new device registration in a victim Entra ID environment.
Attackers abused Microsoft Entra ID's Device Registration Service to enroll rogue devices under compromised user identities, commonly after device-code phishing. The registrations could satisfy device-based Conditional Access requirements and support Microsoft 365 access, email exfiltration, persistence, or tenant expansion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.