Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys — Threadlinqs Intelligence
As of 2026-07-31, Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys is a high-severity phishing threat attributed to Multiple: Storm-2372 (Russia (Storm-2372 attribution, medium confidence); criminal actors are not state-affiliated), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1793 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Multiple: Storm-2372 · Russia (Storm-2372 attribution, medium confidence); criminal actors are not state-affiliated · FINANCIAL
Device code phishing abuses the OAuth 2.0 Device Authorization Grant (RFC 8628) to steal post-authentication access and refresh tokens, defeating every MFA form including FIDO2 passkeys because it
Device code phishing exploits the OAuth 2.0 Device Authorization Grant, a flow designed for input-constrained devices (smart TVs, CLIs, IoT) where a user visits a verification URL on a separate, trusted device and enters a short code to authorize a session. Because the flow is entirely spec-compliant and occurs on the identity provider's own legitimate domain, it structurally bypasses every authentication-layer defense: passwords, OTPs, push MFA, and even phishing-resistant FIDO2/passkey authentication, since "proving your identity and granting access to an application are two different things" and this attack targets only the latter.
The canonical attack chain: an attacker requests a real device code from the identity provider (Microsoft, Salesforce, GitHub, AWS, etc.), then delivers a lure — a fake Teams meeting invite, an IT-helpdesk vishing call, a Telegram-distributed phishing kit lure, or a spoofed verification/CAPTCHA page — that instructs the victim to visit the provider's own legitimate device-login page and enter the attacker-supplied code. The victim authenticates normally and clicks "approve," and the identity provider issues an OAuth access token and refresh token directly to the attacker's polling client. No credentials or MFA codes are ever exposed to the attacker, and no authentication-layer control (conditional access risk scoring aimed at sign-in behavior, MFA fatigue, phishing-resistant hardware keys) fires, because the victim did, in fact, authenticate themselves.
The technique was first described by researchers in 2020 but remained a curiosity until Microsoft's Threat Intelligence Center identified Storm-2372, a threat actor assessed with medium confidence to align with Russian state interests, running an active device code phishing campaign since August 2024 against government, NGO, IT services, defense, telecom, healthcare, higher education, and energy/oil-and-gas targets across Europe, North America, Africa, and the Middle East. Storm-2372 impersonated prominent individuals over WhatsApp, Signal, and Teams to build rapport before sending fake meeting invitations; in February 2025 Microsoft observed the group evolve to abuse the Microsoft Authentication Broker client ID specifically to mint Primary Refresh Tokens (PRTs) and register attacker-controlled devices, extending persistence beyond simple token theft into full device-bound identity compromise that survives password resets.
In 2025-2026 the technique was industrialized as a criminal commodity. ShinyHunters (operating within the Scattered LAPSUS$ Hunters alliance alongside Scattered Spider and LAPSUS$, tracked separately as UNC6040 for the vishing cluster) combined voice phishing — cold-calling victims as fake IT support citing a "mandatory passkey rollout" or compliance issue — with device code phishing against Salesforce's /setup/connect flow, registering attacker-controlled "DataLoader" connected apps that impersonate Salesforce's legitimate Data Loader integration and request broad, refresh-token-capable API scopes. This campaign compromised over 1,000 organizations and produced roughly 1.5 billion stolen records, and was a contributing vector (via a September 2025 Salesforce tenant compromise) to the May 2026 Instructure/Canvas breach affecting approximately 275 million individuals across ~330 school Free-For-Teacher portals. Push Security separately tracked a 37.5x increase in device code phishing activity since the start of 2026 across 12+ distinct kits.
Commercial phishing-as-a-service platforms accelerated adoption further: Sekoia first documented EvilTokens in March 2026 ($1,500 one-time plus $500/month), after which Microsoft VP Tanmay Ganacharya reported 10-15 distinct new campaigns launching every 24 hours. Cisco Talos subsequently exposed ARToken, a React SPA operator panel sharing EvilTokens' API contracts and PRT lifecycle, exposing 80+ API endpoints for device code phishing, PRT persistence (setup/refresh/renew/reacquire/cookie
Target sectors: government administration, ngo, itservices, technology, defense, telecoms, health, higher education, energy, oilandgas, retail, education
Target regions: North America, Europe, Africa, Middle East, Global
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1598, T1583, T1566, T1199, T1098, T1528, T1110, T1539, T1078, T1556