Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability

Device Code Phishing Surge (TL-2026-2468), also tracked as Device Code Phishing, is a high-severity phishing campaign, first published 2026-09-12. It is attributed to EvilTokens with low confidence, affects Microsoft Microsoft 365 / Entra ID (Azure AD) - OAuth 2.0 Device, maps to 13 MITRE ATT&CK techniques (T1078, T1087, T1110.004), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-2468

Threat ID
TL-2026-2468
Also known as
Device Code Phishing, OAuth Device Code Phishing, Device Authorization Grant Phishing
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-12
Last reviewed
2026-09-12
Attribution
EvilTokens
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
it services, hr payroll, legal, financial operations, education, financial services, government administration, health, retail, manufacturing, technology, energy
Target regions
North America, 005 - South America, Europe, Middle East, Africa, Asia, Oceania
Detection rules
9
Indicators of compromise
24

Malware and tooling in Device Code Phishing Surge

Malware and tooling: EvilTokens, Kali365 (aka Octopi365, Freedom365), OctoLink Live, OctoLink Sender

Five commodity phishing-as-a-service kits (Tycoon2FA, EvilTokens, Kali365, Ghost Hub, Cyb3r) have added device code phishing capability, abusing Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow to harvest access and refresh tokens and hijack Microsoft 365 accounts without capturing a password or presenting a fake login page. Tycoon2FA resumed operations within days of a March 4, 2026 Europol/Microsoft takedown by grafting device-code capability onto its existing AiTM infrastructure, while EvilTokens and Kali365 launched in 2026 with AI-augmented post-compromise BEC tooling built in from the start.

How Device Code Phishing Surge works

Device code phishing abuses the OAuth 2.0 Device Authorization Grant flow (RFC 8628), a legitimate mechanism Microsoft built for input-constrained devices (smart TVs, CLIs) to authenticate. An attacker initiates a device authorization request against Microsoft's own endpoint, receives a short-lived user code, and social-engineers a victim into visiting the genuine microsoft.com/devicelogin page and entering that code. Because the victim authenticates on real Microsoft infrastructure with their own password and MFA, no credentials are phished and no fake login page is needed — but the resulting access and refresh tokens are issued to the attacker's device, not the victim's. Refresh tokens persist for up to 90 days and can be exchanged for a Primary Refresh Token (PRT), giving silent, MFA-bypassing SSO access across Microsoft 365 that survives password resets and is immune to phishing-resistant MFA (FIDO2/passkeys), since the bypass targets token issuance rather than the credential itself.

Microsoft first attributed this technique in the wild to Storm-2372, an actor Microsoft assesses (moderate confidence) aligns with Russian state interests, active since August 2024 against government, NGO, IT, defense, telecom, health, education, and energy targets across Europe, North America, Africa, and the Middle East. Storm-2372 built rapport via fake WhatsApp/Signal/Teams meeting invites before steering victims to the device-code lure, then used Microsoft Graph API searches (keywords including "password", "admin", "teamviewer", "anydesk", "credentials", "secret", "ministry", "gov") to harvest sensitive mail and registered actor-controlled devices in Entra ID to mint PRTs.

That nation-state technique has now been industrialized into commodity crimeware. Tycoon2FA — an AiTM credential-relay kit that Microsoft/Europol say accounted for roughly 62% of phishing Microsoft blocked by mid-2025 and enabled over 64,000 attacks — was dismantled on March 4, 2026 in a coalition action (Europol Cyber Intelligence Extension Programme, Microsoft, Trend Micro/TrendAI) that seized 330 domains under a SDNY court order and executed infrastructure seizures across Latvia, Lithuania, Portugal, Poland, Spain, and the UK. Operators resumed within days using the identical 2025 codebase (same hardcoded AES-CBC key/IV, the same performance.now()-based anti-debug timing trap, the same "Check Domain" bot-gate grammar) but shifted hosting to Alibaba Cloud (AS45102) and layered on device-code capability, abusing the Trustifi click-tracking service for link reputation laundering.

EvilTokens, first seen mid-February 2026, is a turnkey device-code PhaaS whose backend the researchers assess with high confidence is AI-generated ("vibe coded"): a single JavaScript service exposing REST endpoints for device-code initiation, Microsoft polling, and PRT conversion, protected by a bot-detection header computed as SHA256(secret + timestamp + "_antibot"). It scaled past 1,000 phishing domains by March 23, 2026, hosted primarily on Cloudflare Workers with a predictable *-s-account.workers.dev naming pattern, and targets finance, HR, logistics, and sales roles across the US, Australia, Canada, France, India, Switzerland, and the UAE for BEC.

Kali365 (also seen rebranded/forked as Octopi365 and Freedom365), first observed April 2026, is the most operationally mature: a three-edition PhaaS with 33 lure templates, 100+ API endpoints, RBAC, a credit-based domain marketplace, and OxaPay crypto billing, hosted heavily on Tencent Cloud (AS132203, concentrated in 43.173.64.0/20) across 240+ IPs. Its Edition 2 integrates Claude Sonnet to triage high-value wire-transfer and invoice email threads and draft BEC replies; its companion Electron desktop apps, OctoLink Live and OctoLink Sender, convert stolen refresh tokens into live browser sessions (via the legitimate Microsoft Office client ID) and mass-send phishing/lateral emails from compromised mailboxes with human-like send cadences designed to evade throttling detection. The FBI issued PSA 2026/PSA260521 warning of Kali365 targeting of US organizations.

Ghost Hub, the admin panel of the Telegram-distributed "Ghost Hacker Operating System" kit, and Cyb3r, which favors funding/investment-themed lures with encrypted PDF attachments, round out the five platforms KnowBe4 and LevelBlue identify as having added device-code capability, part of a broader landscape PushSecurity places at 14+ distinct device-code kits by April 2026 with detections up 37.5x since early March. Across all five kits the end goal is consistent: OAuth token theft leading to mailbox access, business email compromise, and financial fraud, with LLM-driven post-compromise tooling compressing the compromise-to-fraud window from hours to seconds.

MITRE ATT&CK techniques used in TL-2026-2468

Initial Access

T1078 Valid Accounts; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Discovery

T1087 Account Discovery

Credential Access

T1110.004 Credential Stuffing; T1187 Forced Authentication; T1528 Steal Application Access Token

Collection

T1114.002 Remote Email Collection

Persistence

T1137.005 Outlook Rules

Exfiltration

T1537 Transfer Data to Cloud Account

lateral-movement

T1550.001 Application Access Token

Resource Development

T1583.001 Domains

Reconnaissance

T1598.003 Spearphishing Link

Affected products and versions in Device Code Phishing Surge

  • Microsoft — Microsoft 365 / Entra ID (Azure AD) - OAuth 2.0 Device Authorization Grant
    Vulnerable versions: Entra ID tenants with Device Authorization Grant enabled and no Conditional Access restriction on the Device Code authentication flow
    Fixed in: Entra ID tenants with Conditional Access blocking or restricting the Device Code authentication flow to approved users/devices/locations

Remediation for Device Code Phishing Surge

Immediate actions

  • Restrict the OAuth 2.0 Device Authorization Grant flow via Conditional Access policies scoped to approved users, managed devices, and trusted network locations
  • Revoke refresh tokens and Primary Refresh Tokens for any account that authenticated via device code flow outside an expected, user-initiated context
  • Treat any unsolicited device-code prompt as suspicious unless the user personally initiated the device-registration flow

Workarounds

  • Configure browser- or proxy-level warnings when users navigate to microsoft.com/devicelogin outside an expected self-service device-registration flow

Longer-term hardening

  • Disable Device Code Flow entirely in Entra ID tenants that have no operational need for input-constrained device authentication
  • Deploy phishing-resistant MFA (FIDO2/passkeys) as defense-in-depth, while recognizing device-code phishing bypasses even passkey-based MFA because it targets token issuance, not the credential
  • Monitor sign-in logs for device-code authentications from anomalous ASNs (e.g. AS45102 Alibaba, AS132203 Tencent, AS132203-adjacent residential proxies) and flag IP mismatches between authorization and subsequent token use
  • Hunt for Exchange mail-flow rule, mail connector, and DKIM configuration changes and anomalous outbound mail volume following any device-code authentication event

Timeline of Device Code Phishing Surge

  • Storm-2372, a Russia-aligned actor (Microsoft, moderate confidence), begins device code phishing campaigns against government, NGO, IT, defense, telecom, health, education, and energy targets across Europe, North America, Africa, and the Middle East.
  • Microsoft publicly attributes the in-the-wild device code phishing technique to Storm-2372, detailing its Teams/WhatsApp/Signal rapport-building lures and Graph API keyword-search collection.
  • EvilTokens, a turnkey AI-assisted device-code PhaaS kit, begins circulating (Sekoia).
  • A Europol-led coalition with Microsoft and Trend Micro/TrendAI seizes 330 Tycoon2FA domains under a SDNY court order, disrupting infrastructure that had enabled over 64,000 attacks and accounted for ~62% of phishing Microsoft blocked by mid-2025.
  • Tycoon2FA operators resume operations days after the takedown, reusing the identical 2025 codebase (hardcoded AES key/IV, anti-debug timing trap, Check Domain bot-gate) with device-code capability layered onto the existing AiTM kit.
  • EvilTokens infrastructure is identified spanning over 1,000 phishing domains, primarily on Cloudflare Workers (Sekoia).
  • Kali365 is first observed in the wild, per later FBI reporting.
  • PushSecurity reports device code phishing detections up 37.5x since early March 2026, with 14+ distinct device-code kits tracked in circulation.
  • Tycoon2FA device-code infrastructure hosted on Alibaba Cloud (AS45102) becomes active (eSentire).
  • eSentire documents a full Tycoon2FA device-code attack chain sample, from Trustifi-laundered click-tracking link delivery through OAuth token issuance.
  • Huntress SOC first detects unusual device-code authentication activity traced to Tencent Cloud, later attributed to Kali365.
  • Kali365 activity peaks with 80+ successful device-code authentications observed in a single day.
  • The FBI issues PSA 2026/PSA260521 warning of Kali365 targeting US organizations via device code phishing.
  • Huntress publicly discloses the Kali365/Octopi365/Freedom365 PhaaS ecosystem, including its OctoLink Live/Sender tooling and IOC set.
  • KnowBe4 publishes "Device Code Phishing is Surging," identifying Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r as the five commodity kits driving the surge.

Sources cited for Device Code Phishing Surge

More in phishing

Detection coverage for TL-2026-2468

As of 2026-09-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2468 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats