Threat reportPhishingTL-2026-1793

Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys

highACTIVE

Device Code Phishing (TL-2026-1793), also tracked as Device Code Phishing, is a high-severity phishing campaign, first published 2026-07-31. It is attributed to Storm-2372 (Russia) with medium confidence, affects IETF / OAuth Working Group OAuth 2.0 Device Authorization Grant (RFC, maps to 17 MITRE ATT&CK techniques (T1027, T1078, T1098), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
2Storm-2372
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-1793

Threat ID
TL-2026-1793
Also known as
Device Code Phishing, OAuth Device Code Attack, Device Authorization Grant Phishing, Device Code Flow Abuse
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution
Storm-2372, ShinyHunters
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
government administration, ngo, itservices, technology, defense, telecoms, health, higher education, energy, oilandgas, retail, education
Target regions
North America, Europe, Africa, Middle East, Global
Detection rules
9
Indicators of compromise
25

Malware and tooling in Device Code Phishing

Malware and tooling: ARTSender, ARToken, Data Loader (spoofed), EvilTokens, Kali365, Tycoon2FA

How Device Code Phishing works

Device code phishing abuses the OAuth 2.0 Device Authorization Grant (RFC 8628) to steal post-authentication access and refresh tokens, defeating every MFA form including FIDO2 passkeys because it targets the authorization layer rather than login. The technique moved from a 2020 research curiosity to nation-state tradecraft (Storm-2372, since August 2024) to a fully industrialized criminal commodity in 2025-2026 via phishing-as-a-service kits (EvilTokens, ARToken, Tycoon2FA, Kali365, and 25+ others tracked by Push Security), with Microsoft observing 10-15 new campaigns every 24 hours and Barracuda logging 7 million attacks in four weeks (April 2026).

Device code phishing exploits the OAuth 2.0 Device Authorization Grant, a flow designed for input-constrained devices (smart TVs, CLIs, IoT) where a user visits a verification URL on a separate, trusted device and enters a short code to authorize a session. Because the flow is entirely spec-compliant and occurs on the identity provider's own legitimate domain, it structurally bypasses every authentication-layer defense: passwords, OTPs, push MFA, and even phishing-resistant FIDO2/passkey authentication, since "proving your identity and granting access to an application are two different things" and this attack targets only the latter.

The canonical attack chain: an attacker requests a real device code from the identity provider (Microsoft, Salesforce, GitHub, AWS, etc.), then delivers a lure — a fake Teams meeting invite, an IT-helpdesk vishing call, a Telegram-distributed phishing kit lure, or a spoofed verification/CAPTCHA page — that instructs the victim to visit the provider's own legitimate device-login page and enter the attacker-supplied code. The victim authenticates normally and clicks "approve," and the identity provider issues an OAuth access token and refresh token directly to the attacker's polling client. No credentials or MFA codes are ever exposed to the attacker, and no authentication-layer control (conditional access risk scoring aimed at sign-in behavior, MFA fatigue, phishing-resistant hardware keys) fires, because the victim did, in fact, authenticate themselves.

The technique was first described by researchers in 2020 but remained a curiosity until Microsoft's Threat Intelligence Center identified Storm-2372, a threat actor assessed with medium confidence to align with Russian state interests, running an active device code phishing campaign since August 2024 against government, NGO, IT services, defense, telecom, healthcare, higher education, and energy/oil-and-gas targets across Europe, North America, Africa, and the Middle East. Storm-2372 impersonated prominent individuals over WhatsApp, Signal, and Teams to build rapport before sending fake meeting invitations; in February 2025 Microsoft observed the group evolve to abuse the Microsoft Authentication Broker client ID specifically to mint Primary Refresh Tokens (PRTs) and register attacker-controlled devices, extending persistence beyond simple token theft into full device-bound identity compromise that survives password resets.

In 2025-2026 the technique was industrialized as a criminal commodity. ShinyHunters (operating within the Scattered LAPSUS$ Hunters alliance alongside Scattered Spider and LAPSUS$, tracked separately as UNC6040 for the vishing cluster) combined voice phishing — cold-calling victims as fake IT support citing a "mandatory passkey rollout" or compliance issue — with device code phishing against Salesforce's /setup/connect flow, registering attacker-controlled "DataLoader" connected apps that impersonate Salesforce's legitimate Data Loader integration and request broad, refresh-token-capable API scopes. This campaign compromised over 1,000 organizations and produced roughly 1.5 billion stolen records, and was a contributing vector (via a September 2025 Salesforce tenant compromise) to the May 2026 Instructure/Canvas breach affecting approximately 275 million individuals across ~330 school Free-For-Teacher portals. Push Security separately tracked a 37.5x increase in device code phishing activity since the start of 2026 across 12+ distinct kits.

Commercial phishing-as-a-service platforms accelerated adoption further: Sekoia first documented EvilTokens in March 2026 ($1,500 one-time plus $500/month), after which Microsoft VP Tanmay Ganacharya reported 10-15 distinct new campaigns launching every 24 hours. Cisco Talos subsequently exposed ARToken, a React SPA operator panel sharing EvilTokens' API contracts and PRT lifecycle, exposing 80+ API endpoints for device code phishing, PRT persistence (setup/refresh/renew/reacquire/cookie), full Outlook mailbox and SharePoint/OneDrive access, and an automated BEC module ("ARTSender") that sends as the victim, creates evidence-suppressing inbox rules, and monitors compromised mailboxes for keywords in real time — Talos characterized it as "a complete BEC operations environment." ARToken layers a seven-stage client-side anti-bot/anti-analysis system (headless-browser and navigator.webdriver detection, mouse-trajectory validation, 800ms interaction gating) atop a server-side X-Antibot-Token (SHA-256, 5-minute window) and XOR-encrypts delivered payloads to evade static URL scanners. Tycoon2FA — previously the dominant Adversary-in-the-Middle credential-phishing kit, disrupted by a Microsoft/Europol takedown in March 2026 — resurfaced in May 2026 with device code phishing bolted onto its largely intact core kit. The FBI/IC3 issued PSA I-052126-PSA on 21 May 2026, its first advisory naming a specific phishing kit (Kali365), warning that the Telegram-distributed, subscription-based platform lowers the skill barrier via AI-generated lures and real-time victim-tracking dashboards. Barracuda's April 2026 Threat Spotlight logged over 7 million device code attacks in four weeks, describing the technique as fully industrialized under a PhaaS model. A related browser-native technique, ConsentFix (Push Security's Browser & Identity Attacks Matrix ID SAT1051, disclosed December 2025 and initially linked to Russian state-affiliated APT29), abuses trusted first-party OAuth applications and consent-grant flows via a spoofed verification/CAPTCHA page to achieve the same passkey-defeating, post-authentication token theft — evidence that the underlying weakness (authorization-layer trust divorced from authentication-layer defenses) is being exploited through multiple, converging techniques rather than one isolated kit.

Across observed campaigns, Microsoft 365/Entra ID accounts for roughly 99% of detected device code phishing targets, with Salesforce, GitHub, and AWS also confirmed as targeted OAuth 2.0 implementers. Because the flow is a legitimate, spec-compliant protocol feature rather than a software defect, there is no vendor patch; the only effective controls are blocking or conditionally restricting the device authorization grant itself, and behavioral/browser-native detection of the phishing kits' delivery infrastructure rather than IOC-based blocking alone.

MITRE ATT&CK techniques used in TL-2026-1793

Defense Evasion

T1027 Obfuscated Files or Information; T1078 Valid Accounts; T1497 Virtualization/Sandbox Evasion

Persistence

T1098 Account Manipulation

Credential Access

T1110 Brute Force; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

Collection

T1114 Email Collection; T1530 Data from Cloud Storage

Initial Access

T1199 Trusted Relationship; T1566 Phishing

Impact

T1531 Account Access Removal

Lateral Movement

T1534 Internal Spearphishing; T1550 Use Alternate Authentication Material

defense-impairment

T1556 Modify Authentication Process

Resource Development

T1583 Acquire Infrastructure

Reconnaissance

T1598 Phishing for Information

Affected products and versions in Device Code Phishing

  • IETF / OAuth Working Group — OAuth 2.0 Device Authorization Grant (RFC 8628)
    Vulnerable versions: all conformant implementations by design
    Fixed in: N/A — protocol behaves as specified; mitigation is deployment-level restriction, not a spec fix
  • Microsoft — Entra ID / Microsoft 365 device code authentication flow
    Vulnerable versions: all tenants with device code flow enabled and unrestricted
    Fixed in: N/A — mitigated via Conditional Access device-code restriction policies, not a patch
  • Salesforce — Salesforce Setup / Connect App device authorization flow
    Vulnerable versions: all orgs with device flow enabled for connected apps
    Fixed in: N/A — mitigated via connected-app scope review and device-flow restriction
  • GitHub — GitHub OAuth Device Flow
    Vulnerable versions: all OAuth Apps/organizations using device flow
    Fixed in: N/A — mitigated via org-level OAuth app policy restriction
  • Amazon Web Services — AWS IAM Identity Center / CLI device authorization grant
    Vulnerable versions: all accounts using CLI/SSO device authorization
    Fixed in: N/A — mitigated via IAM Identity Center session policy restriction

Remediation for Device Code Phishing

Patches

  • No vendor patch applies — device code phishing abuses a legitimate, spec-compliant OAuth 2.0 feature (RFC 8628 Device Authorization Grant), not a software vulnerability

Immediate actions

  • Block or restrict the OAuth 2.0 device authorization grant via Conditional Access / device-code policies where the flow is not operationally required, across Entra ID, Salesforce Setup/Connect, GitHub, and AWS IAM Identity Center
  • Deploy hunting queries for clicks on microsoft.com/devicelogin and login.microsoftonline.com/common/oauth2/deviceauth correlated with Entra ID sign-in error code 50199 followed by a successful sign-in within 5 minutes
  • Revoke active refresh tokens and Primary Refresh Tokens (revokeSignInSessions) for any account suspected of completing an unsolicited device code prompt, and force re-registration of any device enrolled via the Microsoft Authentication Broker client ID during the suspected window
  • Audit and remove unfamiliar 'Data Loader' or lookalike connected/OAuth apps granted broad, refresh-token-capable API scopes in Salesforce, Microsoft 365, and other SaaS tenants
  • Brief users and helpdesk staff that legitimate IT support will never ask a user to read back, relay, or enter a device code over a phone call, chat, or unsolicited meeting invite

Workarounds

  • Disable the device authorization grant entirely for tenants/organizations with no genuine input-constrained (smart TV/CLI/IoT) use case
  • Where the flow cannot be disabled, restrict it via Conditional Access named-location, compliant-device, and sign-in-risk requirements to shrink the exploitable population

Longer-term hardening

  • Recognize that phishing-resistant MFA (FIDO2/passkeys) does not stop device-code or OAuth-consent (ConsentFix-style) phishing, since both attack the authorization layer post-authentication; layer authorization-time controls (Conditional Access, continuous access evaluation, sign-in risk policies) on top of authentication-time MFA
  • Deploy browser-native/in-browser detection capable of identifying device-code and OAuth-consent phishing pages behaviorally, independent of URL/domain reputation, given the rapid domain and Cloudflare Workers churn used by kits like ARToken
  • Establish continuous OAuth/connected-app governance reviewing consent grants, requested scopes, and third-party integrator trust relationships (e.g., Salesloft/Drift-style supply-chain OAuth abuse)
  • Build persistent hunting content for Primary Refresh Token persistence patterns (setup/refresh/renew/reacquire/cookie cycles) and anomalous device registration events in Entra ID

Timeline of Device Code Phishing

  • Security researchers first publicly describe device code phishing as an abuse path for the OAuth 2.0 Device Authorization Grant.
  • Microsoft Threat Intelligence Center observes Storm-2372, a threat actor assessed with medium confidence to align with Russian state interests, begin an active device code phishing campaign against government, NGO, IT, defense, telecom, healthcare, higher-education, and energy targets across Europe, North America, Africa, and the Middle East.
  • Microsoft publishes a public advisory on the Storm-2372 device code phishing campaign, including tactical evolution toward abusing the Microsoft Authentication Broker client ID to mint Primary Refresh Tokens and register attacker-controlled devices.
  • Push Security discloses ConsentFix, a browser-native OAuth consent-phishing technique (Browser & Identity Attacks Matrix ID SAT1051) that similarly defeats passkeys by exploiting the authorization layer; initial activity linked to Russian state-affiliated APT29.
  • French cybersecurity firm Sekoia documents EvilTokens, a commercial phishing-as-a-service device code phishing kit priced at $1,500 one-time plus $500/month, marking industrialization of the technique as a criminal commodity.
  • Microsoft observes device code phishing campaign volume scale to 10-15 entirely new campaigns launching every 24 hours, per Microsoft VP Tanmay Ganacharya.
  • Barracuda's Threat Spotlight reports over 7 million device code phishing attacks detected in the preceding four weeks, describing the technique as fully industrialized under a PhaaS model.
  • The Instructure/Canvas breach, tracing back to a September 2025 Salesforce tenant compromise, is disclosed as affecting approximately 275 million individuals across roughly 330 Free-For-Teacher school portals.
  • ShinyHunters / Scattered LAPSUS$ Hunters' device-code-plus-vishing campaign against Salesforce tenants is confirmed to have compromised over 1,000 organizations and produced approximately 1.5 billion stolen records, with attacker-registered lookalike 'DataLoader' connected apps as the OAuth abuse vector.
  • The FBI/IC3 issues Public Service Alert I-052126-PSA on the Kali365 phishing-as-a-service kit, its first advisory naming a specific device code phishing kit; Kali365 was first observed in April 2026 and is distributed via Telegram.
  • Tycoon2FA, previously the dominant Adversary-in-the-Middle credential phishing kit disrupted by a March 2026 Microsoft/Europol takedown, resurfaces with device code phishing capability added atop its largely intact core kit (hardcoded expiry timestamp of 2026-05-29T00:00:00Z observed in kit lure pages).
  • Cisco Talos publishes analysis of ARToken, a React SPA phishing-as-a-service operator panel sharing EvilTokens' API contracts, exposing 80+ endpoints for device code phishing, Primary Refresh Token persistence, mailbox/SharePoint access, and automated BEC operations.
  • Microsoft publishes guidance for defending SaaS-based applications against ShinyHunters' OAuth abuse techniques, including device code phishing.
  • The Hacker News publishes '6 Reasons Why Device Code Phishing Is Exploding,' synthesizing the technique's rapid escalation and citing Push Security's tracking of 25+ distinct device code phishing kits.

Sources cited for Device Code Phishing

Detection coverage for TL-2026-1793

As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1793 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats