Threat reportPhishingTL-2026-3086

"Secure Folder" Auth Phishing Campaign Targets Microsoft Accounts via OAuth Device-Code Flow

highACTIVE

"Secure Folder" Auth Phishing Campaign Targets Microsoft (TL-2026-3086) is a high-severity phishing campaign, first published 2026-10-09. It has no confirmed attribution, affects Microsoft Microsoft 365 / Microsoft Entra ID accounts, maps to 10 MITRE ATT&CK techniques (T1078.004, T1114.002, T1204.001), and is covered by 9 detection rules and 13 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-3086

Threat ID
TL-2026-3086
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
13

How "Secure Folder" Auth Phishing Campaign Targets Microsoft works

MailGuard reported on 2026-10-09 a multi-stage phishing campaign that impersonates Dropbox and DocuSign to trick users into completing a Microsoft OAuth device-code sign-in on the genuine login.microsoftonline.com endpoint, giving the attacker access to the victim's mail, files, contacts and SharePoint data without stealing a password. No CVE, CVSS or actor attribution is stated in the source.

MailGuard describes a multi-stage OAuth consent/device-code phishing campaign. The lure email is sent under the display name "RecordsTeam" from kensuke.n@nakabayashi-co.com with a subject such as "Auto-Receipt || The requested submittals for this quote Replacements READY FOR REVIEW", a routine business-document pretext.

Stage 1 is a redirect chain that passes through legitimate services (link.edgepilot.com and secure-web.cisco.com) before landing on artemisabeach.com under a path that imitates a certificate-validation directory (/.well-known__e71c118/pki-validation/gqazbvcb). Stage 2 is a fake Dropbox page claiming a secure folder has been shared, listing a file named _Client_Assets_2026.zip, hosted on musairkompresor.com/uploads/wilderfrress/. Stage 3 is a spoofed DocuSign-style secure document portal on avittti.com/injabazmishelinktoon that tells the victim to copy a code, click "Verify & Paste", and sign in.

The victim is then sent to the genuine Microsoft login endpoint (login.microsoftonline.com). Because authentication happens on Microsoft's real infrastructure, the victim's own sign-in (including any MFA) authorizes the attacker's session. MailGuard states this grants access to email, files, contacts and SharePoint data and gives persistent account access, and that the technique sidesteps password-focused awareness training.

Context from corroborating public reporting (not stated in the MailGuard article, and no link to this campaign is asserted): device-code phishing has been documented by Microsoft since August 2024 (Storm-2372), and a Telegram-sold PhaaS kit called EvilTokens was reported in 2026 with Dropbox/DocuSign-style lures, Cloudflare Workers and Vercel redirect layers, and client-side AES-GCM page obfuscation. Those sources describe post-compromise Microsoft Graph mailbox/OneDrive enumeration, internal phishing from compromised accounts, and attacker device registration in Entra ID. Refresh tokens survive password resets, so remediation needs session/token revocation. This record attributes none of the activity to a specific actor or kit.

MITRE ATT&CK techniques used in TL-2026-3086

Persistence

T1078.004 Cloud Accounts

Collection

T1114.002 Remote Email Collection; T1213.002 Sharepoint; T1530 Data from Cloud Storage

Execution

T1204.001 Malicious Link

Credential Access

T1528 Steal Application Access Token

lateral-movement

T1550.001 Application Access Token

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains

Defense Evasion

T1684.001 Impersonation

Affected products and versions in "Secure Folder" Auth Phishing Campaign Targets Microsoft

  • Microsoft — Microsoft 365 / Microsoft Entra ID accounts
    Vulnerable versions: Tenants that permit OAuth 2.0 device code flow sign-in

Remediation for "Secure Folder" Auth Phishing Campaign Targets Microsoft

Patches

  • No software patch applies; this is abuse of a legitimate authentication flow

Immediate actions

  • Block or sinkhole artemisabeach.com, musairkompresor.com, avittti.com and the sender domain nakabayashi-co.com at mail and web gateways
  • Search mail logs for messages from kensuke.n@nakabayashi-co.com and the "RecordsTeam" display name, and purge delivered copies
  • Search proxy/DNS logs for visits to the listed domains and URL paths; treat any user who visited as potentially compromised
  • For suspected victims, revoke refresh tokens/sessions (revokeSignInSessions) and force re-authentication
  • Review Entra ID sign-in logs for authenticationProtocol deviceCode / originalTransferMethod deviceCodeFlow from unexpected users, IPs or hosting providers

Workarounds

  • Block the OAuth device code flow with an Entra Conditional Access policy (authentication flows condition) and allow it only for trusted devices or networks where required
  • Audit OAuth application consents and device registrations in the tenant and remove unknown entries

Longer-term hardening

  • Enforce phishing-resistant MFA (FIDO2 / passkeys) for Microsoft 365 users
  • Add sign-in risk policies and continuous access evaluation
  • Train users that a code they are told to copy and paste into a Microsoft sign-in page is a phishing indicator, even when the page is genuinely Microsoft's
  • Inspect and rewrite or distrust links that pass through third-party redirect/URL-protection services in mail filtering

Timeline of "Secure Folder" Auth Phishing Campaign Targets Microsoft

  • Microsoft reports it has observed device code phishing (Storm-2372) since August 2024; context for the technique, not linked to this campaign (month-level date).
  • Microsoft publishes Storm-2372 device code phishing analysis with mitigation guidance, including blocking device code flow via Conditional Access.
  • EvilTokens device-code PhaaS kit launched on Telegram per CSA; no link to this campaign is established.
  • CSA research note reports 340+ Microsoft 365 organizations hit by OAuth device code phishing (Dropbox/DocuSign-style lures among those observed).
  • Mimecast reports first detection of a Mimecast device-enrollment device code lure; over 50,000 such campaigns noted since March 2026.
  • MailGuard publishes analysis of the "Secure Folder" campaign: fake Dropbox shared-folder page, DocuSign-style portal, and device-code sign-in on login.microsoftonline.com.

Sources cited for "Secure Folder" Auth Phishing Campaign Targets Microsoft

Detection coverage for TL-2026-3086

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3086 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-3086

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats