Attackers are abusing the OAuth 2.0 Device Authorization Grant to obtain Microsoft 365 account tokens without stealing passwords. They initiate a legitimate device-code sign-in on an attacker-controlled application or device, then persuade targets through meeting, document-sharing, chat, or security-themed lures to enter the supplied temporary code on a genuine Microsoft sign-in page. Because victims complete the authentication and consent themselves, URL checks and MFA may not stop the attack; the resulting tokens can expose email, files, contacts, and other authorized services.
Post-authentication activity can include device registration or Primary Refresh Token issuance, Microsoft Graph queries, mailbox access, and Exchange inbox rules that hide alerts or forward data externally. Defenders should correlate phishing delivery and click telemetry with device-code sign-ins, new-device events, Graph activity, and mailbox-rule changes; contain confirmed incidents by revoking sessions and refresh tokens, disabling unrecognized devices, removing malicious rules, and assessing accessed data. Microsoft recommends blocking device-code flow by default with Entra Conditional Access, first in report-only mode, while maintaining tightly scoped persistent exceptions for legitimate Teams resource accounts and excluding the Device Registration Service where required for enrollment.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A Microsoft 365 device-code phishing sequence was described in which stolen tokens can be used to register devices, query Microsoft Graph, access email, and create mailbox rules to conceal activity or forward data. The post recommends correlating phishing delivery with device-code authentication, subsequent device or PRT issuance, Graph activity, and mailbox-rule changes.
Reports describe attackers initiating legitimate OAuth 2.0 Device Authorization Grant sessions and socially engineering victims to enter attacker-supplied codes on genuine sign-in pages, thereby issuing account tokens to attacker-controlled devices. The reports identify EvilTokens as a phishing kit supporting this technique and note that victim-completed MFA may not prevent it.
Microsoft recommends blocking device code flow by default with Microsoft Entra Conditional Access, using narrowly scoped persistent exceptions for legitimate Teams device resource accounts and excluding the Device Registration Service. It advises report-only deployment, sign-in-log review, and continuous auditing of exceptions and unexpected usage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcereddit.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.