Threat reportPhishingTL-2026-3086
"Secure Folder" Auth Phishing Campaign Targets Microsoft Accounts via OAuth Device-Code Flow
"Secure Folder" Auth Phishing Campaign Targets Microsoft (TL-2026-3086) is a high-severity phishing campaign, first published 2026-10-09. It has no confirmed attribution, affects Microsoft Microsoft 365 / Microsoft Entra ID accounts, maps to 10 MITRE ATT&CK techniques (T1078.004, T1114.002, T1204.001), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-3086
- Threat ID
- TL-2026-3086
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 13
How "Secure Folder" Auth Phishing Campaign Targets Microsoft works
MailGuard reported on 2026-10-09 a multi-stage phishing campaign that impersonates Dropbox and DocuSign to trick users into completing a Microsoft OAuth device-code sign-in on the genuine login.microsoftonline.com endpoint, giving the attacker access to the victim's mail, files, contacts and SharePoint data without stealing a password. No CVE, CVSS or actor attribution is stated in the source.
MailGuard describes a multi-stage OAuth consent/device-code phishing campaign. The lure email is sent under the display name "RecordsTeam" from kensuke.n@nakabayashi-co.com with a subject such as "Auto-Receipt || The requested submittals for this quote Replacements READY FOR REVIEW", a routine business-document pretext.
Stage 1 is a redirect chain that passes through legitimate services (link.edgepilot.com and secure-web.cisco.com) before landing on artemisabeach.com under a path that imitates a certificate-validation directory (/.well-known__e71c118/pki-validation/gqazbvcb). Stage 2 is a fake Dropbox page claiming a secure folder has been shared, listing a file named _Client_Assets_2026.zip, hosted on musairkompresor.com/uploads/wilderfrress/. Stage 3 is a spoofed DocuSign-style secure document portal on avittti.com/injabazmishelinktoon that tells the victim to copy a code, click "Verify & Paste", and sign in.
The victim is then sent to the genuine Microsoft login endpoint (login.microsoftonline.com). Because authentication happens on Microsoft's real infrastructure, the victim's own sign-in (including any MFA) authorizes the attacker's session. MailGuard states this grants access to email, files, contacts and SharePoint data and gives persistent account access, and that the technique sidesteps password-focused awareness training.
Context from corroborating public reporting (not stated in the MailGuard article, and no link to this campaign is asserted): device-code phishing has been documented by Microsoft since August 2024 (Storm-2372), and a Telegram-sold PhaaS kit called EvilTokens was reported in 2026 with Dropbox/DocuSign-style lures, Cloudflare Workers and Vercel redirect layers, and client-side AES-GCM page obfuscation. Those sources describe post-compromise Microsoft Graph mailbox/OneDrive enumeration, internal phishing from compromised accounts, and attacker device registration in Entra ID. Refresh tokens survive password resets, so remediation needs session/token revocation. This record attributes none of the activity to a specific actor or kit.
MITRE ATT&CK techniques used in TL-2026-3086
Persistence
Collection
T1114.002 Remote Email Collection; T1213.002 Sharepoint; T1530 Data from Cloud Storage
Execution
Credential Access
T1528 Steal Application Access Token
lateral-movement
T1550.001 Application Access Token
Initial Access
Resource Development
Defense Evasion
Affected products and versions in "Secure Folder" Auth Phishing Campaign Targets Microsoft
- Microsoft — Microsoft 365 / Microsoft Entra ID accounts
Vulnerable versions: Tenants that permit OAuth 2.0 device code flow sign-in
Remediation for "Secure Folder" Auth Phishing Campaign Targets Microsoft
Patches
- No software patch applies; this is abuse of a legitimate authentication flow
Immediate actions
- Block or sinkhole artemisabeach.com, musairkompresor.com, avittti.com and the sender domain nakabayashi-co.com at mail and web gateways
- Search mail logs for messages from kensuke.n@nakabayashi-co.com and the "RecordsTeam" display name, and purge delivered copies
- Search proxy/DNS logs for visits to the listed domains and URL paths; treat any user who visited as potentially compromised
- For suspected victims, revoke refresh tokens/sessions (revokeSignInSessions) and force re-authentication
- Review Entra ID sign-in logs for authenticationProtocol deviceCode / originalTransferMethod deviceCodeFlow from unexpected users, IPs or hosting providers
Workarounds
- Block the OAuth device code flow with an Entra Conditional Access policy (authentication flows condition) and allow it only for trusted devices or networks where required
- Audit OAuth application consents and device registrations in the tenant and remove unknown entries
Longer-term hardening
- Enforce phishing-resistant MFA (FIDO2 / passkeys) for Microsoft 365 users
- Add sign-in risk policies and continuous access evaluation
- Train users that a code they are told to copy and paste into a Microsoft sign-in page is a phishing indicator, even when the page is genuinely Microsoft's
- Inspect and rewrite or distrust links that pass through third-party redirect/URL-protection services in mail filtering
Timeline of "Secure Folder" Auth Phishing Campaign Targets Microsoft
- Microsoft reports it has observed device code phishing (Storm-2372) since August 2024; context for the technique, not linked to this campaign (month-level date).
- Microsoft publishes Storm-2372 device code phishing analysis with mitigation guidance, including blocking device code flow via Conditional Access.
- EvilTokens device-code PhaaS kit launched on Telegram per CSA; no link to this campaign is established.
- CSA research note reports 340+ Microsoft 365 organizations hit by OAuth device code phishing (Dropbox/DocuSign-style lures among those observed).
- Mimecast reports first detection of a Mimecast device-enrollment device code lure; over 50,000 such campaigns noted since March 2026.
- MailGuard publishes analysis of the "Secure Folder" campaign: fake Dropbox shared-folder page, DocuSign-style portal, and device-code sign-in on login.microsoftonline.com.
Sources cited for "Secure Folder" Auth Phishing Campaign Targets Microsoft
- A new "Secure Folder" Auth phishing scam targets Microsoft accounts (MailGuard)
- Storm-2372 conducts device code phishing campaign (Microsoft Security Blog)
- CSA Research Note: OAuth Device Code Phishing Hits 340+ Microsoft 365 Organizations
- OAuth Device Code Phishing Campaigns Surge with EvilTokens Toolkit (Mimecast)
- Microsoft: Hackers Steal Emails in Device Code Phishing Attacks (BleepingComputer)
- The new hotness in phishing: device code attacks in M365 (TrustedSec)
- How to protect against Device Code Flow abuse (Storm-2372 attacks) and block the authentication flow
- CIS Microsoft 365 Foundations 5.2.2.12: Ensure the device code sign-in flow is blocked
Detection coverage for TL-2026-3086
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3086 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-3086
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.