Threat reportPhishingTL-2026-1492
Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant Abuse
Device Code Phishing Campaign Targets Microsoft 365 via (TL-2026-1492), also tracked as OAuth Device Code Phishing (ReversingLabs cluster), is a high-severity phishing campaign, first published 2026-07-18. It has no confirmed attribution, affects Microsoft Microsoft 365 / Entra ID (Azure AD) — OAuth 2.0 Device, maps to 16 MITRE ATT&CK techniques (T1027, T1036, T1071.001), and is covered by 9 detection rules and 19 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-1492
- Threat ID
- TL-2026-1492
- Also known as
- OAuth Device Code Phishing (ReversingLabs cluster), ClickFix-style Device Code Phishing
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, manufacturing, finance, health, professional-services
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Device Code Phishing Campaign Targets Microsoft 365 via
Malware and tooling: DeviceCode_Phishing_LandingPageHTML
How Device Code Phishing Campaign Targets Microsoft 365 via works
ReversingLabs documents an active, unattributed phishing campaign that abuses Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow to hijack Microsoft 365 / Entra ID accounts without stealing passwords. Business-themed lures direct victims to a ClickFix-style landing page that walks them through entering an attacker-supplied device code into the genuine Microsoft login flow, silently authorizing an attacker-controlled device and granting persistent account access.
The campaign begins with phishing emails carrying HTML attachments styled as business documents (e.g., vendor estimates/quotes). The HTML references JPG lure imagery via Content-ID URLs wrapped in clickable anchor tags with algorithmically generated ID parameters, evading static content matching. Clicking through lands the victim on a ClickFix-style page requesting 'document review,' which displays a verification/device code and instructs the victim to copy it and sign in via Microsoft. The sign-in button opens a genuine Microsoft authentication popup (via window.open() to the legitimate aka.ms/devicelogin, Akamai-hosted) — the victim enters the phishing-supplied device code into Microsoft's own, real interface. On completion, the victim unknowingly authorizes the attacker's registered device against their account, granting the attacker OAuth access/refresh tokens without ever touching or transmitting the victim's password. This is a device-code variant of adversary-in-the-middle (AiTM) phishing: rather than proxying credentials through a fake portal, the attacker relays a legitimate device-authorization code and lets Microsoft's real infrastructure do the authentication, which lets the campaign sail past classic anti-phishing detections that look for spoofed login pages or credential-harvesting POSTs. The phishing kit's backend polls for device-code completion via POST requests roughly every four seconds using URL-safe base64 encoding, mirroring the standard OAuth device-flow polling interval used by legitimate CLI/IoT clients. Technical/evasion notables: the landing-page HTML embeds invisible Unicode formatting characters — Zero Width Space (U+200B), Word Joiner (U+2060), and Zero Width Non-Joiner (U+200C) — inside high-signal words such as 'Agreement,' 'Verify,' and 'Microsoft' to defeat keyword-based phishing detection. A bitshifted artifact string tied to Microsoft Entra ID's Security Token Service ('EvoStsArtifacts') appears in the page and requires a left-shift-by-6-bits transform before base64 decoding, an anti-analysis/obfuscation touch. Infrastructure abuses Cloudflare Workers (*.workers.dev subdomains) alongside a rotating set of freshly registered or compromised domains (300+ URLs catalogued by ReversingLabs) to host landing pages and evade domain-reputation blocking, while calling out to genuinely Microsoft-owned endpoints (aka.ms, login.microsoftonline.com, aadcdn.msftauth.net, login.live.com, browser.events.data.microsoft.com) for the real authentication leg — producing a DNS/network fingerprint that blends malicious and legitimate Microsoft traffic. No CVE or software vulnerability is involved; this is pure abuse of a legitimate, MFA-adjacent authentication flow designed for input-constrained devices (smart TVs, CLIs) that was never intended to be surfaced to end users via a phishing lure. The technique class is not new — Microsoft's Storm-2372 (a suspected Russia-aligned actor) has run device-code phishing against government, NGO, defense, telecom, and energy-sector targets since August 2024, evolving by February 2025 to register attacker devices and mint Primary Refresh Tokens for deeper persistence — and a broader wave of OAuth device-code phishing (340+ M365 organizations across five countries) was reported by industry researchers in March 2026, with Microsoft publishing a follow-up on an AI-enabled variant in April 2026. The ReversingLabs campaign analyzed here is a distinct, unattributed cluster sharing the same technique class, landing-page kit style (ClickFix), and infrastructure-abuse patterns (workers.dev) as those broader waves, but the source does not attribute it to Storm-2372 or any other named actor.
MITRE ATT&CK techniques used in TL-2026-1492
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Command and Control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication
Persistence
command-and-control
Execution
Credential Access
T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation
Impact
lateral-movement
T1550.001 Application Access Token
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
T1583.006 Web Services; T1584.001 Domains
reconnaissance
Affected products and versions in Device Code Phishing Campaign Targets Microsoft 365 via
- Microsoft — Microsoft 365 / Entra ID (Azure AD) — OAuth 2.0 Device Authorization Grant flow
Vulnerable versions: Any tenant with device code authentication flow enabled
Fixed in: Tenants with device code flow blocked or scoped via Conditional Access
Remediation for Device Code Phishing Campaign Targets Microsoft 365 via
Immediate actions
- Block or restrict the OAuth 2.0 Device Authorization Grant flow in Microsoft Entra ID Conditional Access policies for users/roles that do not require it
- Deploy the ReversingLabs YARA rule (DeviceCode_Phishing_LandingPageHTML) at email/web gateways to detect landing pages containing invisible Unicode formatting characters near device-code/verification keywords
- Block known campaign domains and workers.dev subdomains identified in the ReversingLabs IOC list at web/email proxy
- Alert on Entra ID sign-in logs where authentication method = device code, especially from unmanaged/unregistered devices
Workarounds
- Disable the device code authentication flow tenant-wide via Conditional Access if no legitimate business use case exists
Longer-term hardening
- Where device code flow is operationally required (CLI/IoT), scope it via Conditional Access to specific named applications, locations, and compliant/managed devices only
- Deploy network detection for the identified two-phase DNS sequence (phishing host -> aka.ms -> login.microsoftonline.com -> aadcdn.msftauth.net -> login.live.com, followed by the post-code-entry sequence) combined with ~4-second interval beacon POSTs
- Enable Continuous Access Evaluation (CAE) and token binding where available to reduce the value of stolen device-flow tokens
- User-awareness training specifically covering device-code prompts and 'enter this code on another device' language, distinct from generic phishing-link training
Timeline of Device Code Phishing Campaign Targets Microsoft 365 via
- Microsoft Threat Intelligence first tracks Storm-2372 running device-code phishing against government, NGO, defense, telecom, and energy-sector targets — establishing the technique class this campaign belongs to.
- Microsoft publishes analysis of Storm-2372's shift (observed Feb 14, 2025) to registering attacker-controlled devices via the Authentication Broker client ID and minting Primary Refresh Tokens for deeper persistence.
- Sophos publishes 'OAuth's Device Code Flow Abused in Phishing Attacks,' corroborating the technique class and reinforcing detection guidance ahead of the ReversingLabs disclosure.
- Proofpoint publishes 'Access granted: phishing with device code authorization for account takeover,' documenting device-code phishing as an emerging account-takeover vector against enterprise Microsoft 365 tenants.
- Industry researchers (Cloud Security Alliance / The Hacker News) report a broader OAuth device-code phishing wave hitting 340+ Microsoft 365 organizations across five countries.
- Microsoft Security publishes follow-up analysis of an AI-enabled device-code phishing campaign, reflecting continued evolution of the technique class.
- The ReversingLabs-documented campaign is observed actively delivering business-themed (vendor estimate) phishing lures leading to a ClickFix-style device-code landing page, ahead of public disclosure.
- ReversingLabs publishes full technical analysis of the campaign, including 300+ malicious URL IOCs, the Unicode-obfuscation and bitshifted-string techniques, and a detection YARA rule (DeviceCode_Phishing_LandingPageHTML).
- Campaign ingested into the Threadlinqs Intelligence platform for detection-engineering coverage (TL-2026-1492).
Sources cited for Device Code Phishing Campaign Targets Microsoft 365 via
- Device Code Phishing Campaign
- Storm-2372 conducts device code phishing campaign
- Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
- OAuth Device Code Phishing Hits 340+ Microsoft 365 Organizations
- Access granted: phishing with device code authorization for account takeover
- Inside an AI-enabled device code phishing campaign
- OAuth's Device Code Flow Abused in Phishing Attacks
- Steal Application Access Token, Technique T1528 - MITRE ATT&CK
Detection coverage for TL-2026-1492
As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1492 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.