Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device Authorization Grant Abuse (Storm-2372, EvilTokens, Kali365) — Threadlinqs Intelligence
As of 2026-06-25, Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device Authorization Grant Abuse (Storm-2372, EvilTokens, Kali365) is a high-severity phishing threat attributed to Storm-2372 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-0943 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Storm-2372 · Russia · ESPIONAGE
Adversaries abuse Microsoft's legitimate OAuth 2.0 device authorization grant flow: they generate device codes with first-party public client IDs (Azure CLI, Microsoft Authentication Broker, Microsoft
Device code phishing weaponizes the OAuth 2.0 device authorization grant (RFC 8628), a flow designed for input-constrained devices (TVs, IoT, CLI tools). In the legitimate flow a device requests a device_code and a short human-readable user_code from the authorization server, displays the user_code with a verification URL (microsoft.com/devicelogin), and polls the token endpoint until the user approves on a second device; it then receives a scoped, time-limited, revocable access token. Because the flow is a Microsoft first-party, fully legitimate sign-in, it produces no consent prompt and no application warning.
In the attack, the adversary plays the role of the 'device.' The attacker initiates a device_code request against login.microsoftonline.com/oauth2/v2.0/devicecode using a public first-party client ID that requires no app registration or secret — most commonly Azure CLI (04b07795-8ddb-461a-bbee-02f9e1bf7b46), the Microsoft Office client (d3590ed6-52b3-4102-aeff-aad2292ab01c), or, for device-registration abuse, the Microsoft Authentication Broker (29d9ed98-a469-4536-ade2-f981bc1d605e). The attacker wraps the resulting user_code and the genuine microsoft.com/devicelogin URL into a convincing lure (Teams/meeting invite, document-share notice, voicemail, RFQ/bid solicitation, DocuSign, Microsoft Forms) delivered by email or via messaging services (Microsoft Teams, WhatsApp, Signal). When the victim enters the code and authenticates — often silently via existing SSO — the attacker's polling loop instantly receives a valid access_token and refresh_token. Because the tokens are stolen rather than the password, multi-factor authentication is satisfied during the legitimate sign-in and provides no protection.
Storm-2372 (suspected Russian state-aligned, active since August 2024) ran a campaign documented by Microsoft in February 2025, impersonating prominent contacts to build rapport before sending device-code lures, then using the stolen tokens for Microsoft Graph email harvesting (searching mailboxes for keywords such as username, password, admin, teamviewer, anydesk, credentials, secret, ministry, gov). On 14 February 2025 Microsoft documented an evolution: Storm-2372 shifted to the Microsoft Authentication Broker client ID to obtain a refresh token for the device registration service and register attacker-controlled devices in Entra ID, yielding a Primary Refresh Token (PRT) for durable access, while using region-appropriate proxies to blend in. The EvilTokens phishing-as-a-service platform — launched publicly on Telegram on 16 February 2026 with tiered email-delivery, token-capture, and SMTP-relay services and AI-assisted lure customization — ran a large-scale campaign observed from 19 February through mid-March 2026 against 340+ Microsoft 365 organizations across the US, Canada, Australia, New Zealand, and Germany, using Railway.com as the token-harvesting backend behind Cloudflare Workers and Vercel redirect chains. The Kali365 PhaaS platform likewise incorporates device code phishing. Defensive controls center on Conditional Access policies that block the device code flow (including the 'Other clients' / authenticationProtocol = deviceCode condition), phishing-resistant MFA (FIDO2/passkeys), device-registration restrictions, and revocation of refresh tokens via revokeSignInSessions on suspected compromise.
Weaknesses (CWE)
CWE-1390, CWE-287, CWE-1021
Target sectors: government, ngo, defense, telecommunications, healthcare, higher-education, energy, oil-and-gas, it-services, technology, construction, real-estate
Target regions: Europe, North America, Africa, Middle East, Australia, New Zealand
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1587, T1608, T1598, T1566, T1566, T1528, T1606, T1556