Threat reportPhishingTL-2026-1492

Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant Abuse

highACTIVE

Device Code Phishing Campaign Targets Microsoft 365 via (TL-2026-1492), also tracked as OAuth Device Code Phishing (ReversingLabs cluster), is a high-severity phishing campaign, first published 2026-07-18. It has no confirmed attribution, affects Microsoft Microsoft 365 / Entra ID (Azure AD) — OAuth 2.0 Device, maps to 16 MITRE ATT&CK techniques (T1027, T1036, T1071.001), and is covered by 9 detection rules and 19 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
19Indicators of compromise

Key facts for TL-2026-1492

Threat ID
TL-2026-1492
Also known as
OAuth Device Code Phishing (ReversingLabs cluster), ClickFix-style Device Code Phishing
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, manufacturing, finance, health, professional-services
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
19

Malware and tooling in Device Code Phishing Campaign Targets Microsoft 365 via

Malware and tooling: DeviceCode_Phishing_LandingPageHTML

How Device Code Phishing Campaign Targets Microsoft 365 via works

ReversingLabs documents an active, unattributed phishing campaign that abuses Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow to hijack Microsoft 365 / Entra ID accounts without stealing passwords. Business-themed lures direct victims to a ClickFix-style landing page that walks them through entering an attacker-supplied device code into the genuine Microsoft login flow, silently authorizing an attacker-controlled device and granting persistent account access.

The campaign begins with phishing emails carrying HTML attachments styled as business documents (e.g., vendor estimates/quotes). The HTML references JPG lure imagery via Content-ID URLs wrapped in clickable anchor tags with algorithmically generated ID parameters, evading static content matching. Clicking through lands the victim on a ClickFix-style page requesting 'document review,' which displays a verification/device code and instructs the victim to copy it and sign in via Microsoft. The sign-in button opens a genuine Microsoft authentication popup (via window.open() to the legitimate aka.ms/devicelogin, Akamai-hosted) — the victim enters the phishing-supplied device code into Microsoft's own, real interface. On completion, the victim unknowingly authorizes the attacker's registered device against their account, granting the attacker OAuth access/refresh tokens without ever touching or transmitting the victim's password. This is a device-code variant of adversary-in-the-middle (AiTM) phishing: rather than proxying credentials through a fake portal, the attacker relays a legitimate device-authorization code and lets Microsoft's real infrastructure do the authentication, which lets the campaign sail past classic anti-phishing detections that look for spoofed login pages or credential-harvesting POSTs. The phishing kit's backend polls for device-code completion via POST requests roughly every four seconds using URL-safe base64 encoding, mirroring the standard OAuth device-flow polling interval used by legitimate CLI/IoT clients. Technical/evasion notables: the landing-page HTML embeds invisible Unicode formatting characters — Zero Width Space (U+200B), Word Joiner (U+2060), and Zero Width Non-Joiner (U+200C) — inside high-signal words such as 'Agreement,' 'Verify,' and 'Microsoft' to defeat keyword-based phishing detection. A bitshifted artifact string tied to Microsoft Entra ID's Security Token Service ('EvoStsArtifacts') appears in the page and requires a left-shift-by-6-bits transform before base64 decoding, an anti-analysis/obfuscation touch. Infrastructure abuses Cloudflare Workers (*.workers.dev subdomains) alongside a rotating set of freshly registered or compromised domains (300+ URLs catalogued by ReversingLabs) to host landing pages and evade domain-reputation blocking, while calling out to genuinely Microsoft-owned endpoints (aka.ms, login.microsoftonline.com, aadcdn.msftauth.net, login.live.com, browser.events.data.microsoft.com) for the real authentication leg — producing a DNS/network fingerprint that blends malicious and legitimate Microsoft traffic. No CVE or software vulnerability is involved; this is pure abuse of a legitimate, MFA-adjacent authentication flow designed for input-constrained devices (smart TVs, CLIs) that was never intended to be surfaced to end users via a phishing lure. The technique class is not new — Microsoft's Storm-2372 (a suspected Russia-aligned actor) has run device-code phishing against government, NGO, defense, telecom, and energy-sector targets since August 2024, evolving by February 2025 to register attacker devices and mint Primary Refresh Tokens for deeper persistence — and a broader wave of OAuth device-code phishing (340+ M365 organizations across five countries) was reported by industry researchers in March 2026, with Microsoft publishing a follow-up on an AI-enabled variant in April 2026. The ReversingLabs campaign analyzed here is a distinct, unattributed cluster sharing the same technique class, landing-page kit style (ClickFix), and infrastructure-abuse patterns (workers.dev) as those broader waves, but the source does not attribute it to Storm-2372 or any other named actor.

MITRE ATT&CK techniques used in TL-2026-1492

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication

Persistence

T1098.005 Device Registration

command-and-control

T1102 Web Service

Execution

T1204.001 Malicious Link

Credential Access

T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation

Impact

T1531 Account Access Removal

lateral-movement

T1550.001 Application Access Token

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1583.006 Web Services; T1584.001 Domains

reconnaissance

T1598 Phishing for Information

Affected products and versions in Device Code Phishing Campaign Targets Microsoft 365 via

  • Microsoft — Microsoft 365 / Entra ID (Azure AD) — OAuth 2.0 Device Authorization Grant flow
    Vulnerable versions: Any tenant with device code authentication flow enabled
    Fixed in: Tenants with device code flow blocked or scoped via Conditional Access

Remediation for Device Code Phishing Campaign Targets Microsoft 365 via

Immediate actions

  • Block or restrict the OAuth 2.0 Device Authorization Grant flow in Microsoft Entra ID Conditional Access policies for users/roles that do not require it
  • Deploy the ReversingLabs YARA rule (DeviceCode_Phishing_LandingPageHTML) at email/web gateways to detect landing pages containing invisible Unicode formatting characters near device-code/verification keywords
  • Block known campaign domains and workers.dev subdomains identified in the ReversingLabs IOC list at web/email proxy
  • Alert on Entra ID sign-in logs where authentication method = device code, especially from unmanaged/unregistered devices

Workarounds

  • Disable the device code authentication flow tenant-wide via Conditional Access if no legitimate business use case exists

Longer-term hardening

  • Where device code flow is operationally required (CLI/IoT), scope it via Conditional Access to specific named applications, locations, and compliant/managed devices only
  • Deploy network detection for the identified two-phase DNS sequence (phishing host -> aka.ms -> login.microsoftonline.com -> aadcdn.msftauth.net -> login.live.com, followed by the post-code-entry sequence) combined with ~4-second interval beacon POSTs
  • Enable Continuous Access Evaluation (CAE) and token binding where available to reduce the value of stolen device-flow tokens
  • User-awareness training specifically covering device-code prompts and 'enter this code on another device' language, distinct from generic phishing-link training

Timeline of Device Code Phishing Campaign Targets Microsoft 365 via

  • Microsoft Threat Intelligence first tracks Storm-2372 running device-code phishing against government, NGO, defense, telecom, and energy-sector targets — establishing the technique class this campaign belongs to.
  • Microsoft publishes analysis of Storm-2372's shift (observed Feb 14, 2025) to registering attacker-controlled devices via the Authentication Broker client ID and minting Primary Refresh Tokens for deeper persistence.
  • Sophos publishes 'OAuth's Device Code Flow Abused in Phishing Attacks,' corroborating the technique class and reinforcing detection guidance ahead of the ReversingLabs disclosure.
  • Proofpoint publishes 'Access granted: phishing with device code authorization for account takeover,' documenting device-code phishing as an emerging account-takeover vector against enterprise Microsoft 365 tenants.
  • Industry researchers (Cloud Security Alliance / The Hacker News) report a broader OAuth device-code phishing wave hitting 340+ Microsoft 365 organizations across five countries.
  • Microsoft Security publishes follow-up analysis of an AI-enabled device-code phishing campaign, reflecting continued evolution of the technique class.
  • The ReversingLabs-documented campaign is observed actively delivering business-themed (vendor estimate) phishing lures leading to a ClickFix-style device-code landing page, ahead of public disclosure.
  • ReversingLabs publishes full technical analysis of the campaign, including 300+ malicious URL IOCs, the Unicode-obfuscation and bitshifted-string techniques, and a detection YARA rule (DeviceCode_Phishing_LandingPageHTML).
  • Campaign ingested into the Threadlinqs Intelligence platform for detection-engineering coverage (TL-2026-1492).

Sources cited for Device Code Phishing Campaign Targets Microsoft 365 via

Detection coverage for TL-2026-1492

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1492 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
19 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats