# "Secure Folder" Auth Phishing Campaign Targets Microsoft Accounts via OAuth Device-Code Flow

> MailGuard reported on 2026-10-09 a multi-stage phishing campaign that impersonates Dropbox and DocuSign to trick users into completing a Microsoft OAuth device-code sign-in on the genuine login.microsoftonline.com endpoint, giving the attacker access to the victim's mail, files, contacts and SharePoint data without stealing a password. No CVE, CVSS or actor attribution is stated in the source.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3086
- **ID:** TL-2026-3086
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

MailGuard describes a multi-stage OAuth consent/device-code phishing campaign. The lure email is sent under the display name "RecordsTeam" from kensuke.n@nakabayashi-co.com with a subject such as "Auto-Receipt || The requested submittals for this quote Replacements READY FOR REVIEW", a routine business-document pretext.

Stage 1 is a redirect chain that passes through legitimate services (link.edgepilot.com and secure-web.cisco.com) before landing on artemisabeach.com under a path that imitates a certificate-validation directory (/.well-known__e71c118/pki-validation/gqazbvcb). Stage 2 is a fake Dropbox page claiming a secure folder has been shared, listing a file named _Client_Assets_2026.zip, hosted on musairkompresor.com/uploads/wilderfrress/. Stage 3 is a spoofed DocuSign-style secure document portal on avittti.com/injabazmishelinktoon that tells the victim to copy a code, click "Verify & Paste", and sign in.

The victim is then sent to the genuine Microsoft login endpoint (login.microsoftonline.com). Because authentication happens on Microsoft's real infrastructure, the victim's own sign-in (including any MFA) authorizes the attacker's session. MailGuard states this grants access to email, files, contacts and SharePoint data and gives persistent account access, and that the technique sidesteps password-focused awareness training.

Context from corroborating public reporting (not stated in the MailGuard article, and no link to this campaign is asserted): device-code phishing has been documented by Microsoft since August 2024 (Storm-2372), and a Telegram-sold PhaaS kit called EvilTokens was reported in 2026 with Dropbox/DocuSign-style lures, Cloudflare Workers and Vercel redirect layers, and client-side AES-GCM page obfuscation. Those sources describe post-compromise Microsoft Graph mailbox/OneDrive enumeration, internal phishing from compromised accounts, and attacker device registration in Entra ID. Refresh tokens survive password resets, so remediation needs session/token revocation. This record attributes none of the activity to a specific actor or kit.

## MITRE ATT&CK

- T1583.001 Domains
- T1566.002 Spearphishing Link
- T1684.001 Impersonation
- T1204.001 Malicious Link
- T1528 Steal Application Access Token
- T1550.001 Application Access Token
- T1078.004 Cloud Accounts
- T1114.002 Remote Email Collection
- T1530 Data from Cloud Storage
- T1213.002 Sharepoint

## Sources

- [A new "Secure Folder" Auth phishing scam targets Microsoft accounts (MailGuard)](https://www.mailguard.com.au/blog/a-new-secure-folder-auth-phishing-scam-targets-microsoft-accounts)
- [Storm-2372 conducts device code phishing campaign (Microsoft Security Blog)](https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/)
- [CSA Research Note: OAuth Device Code Phishing Hits 340+ Microsoft 365 Organizations](https://labs.cloudsecurityalliance.org/research/csa-research-note-oauth-device-code-phishing-m365-20260325-c/)
- [OAuth Device Code Phishing Campaigns Surge with EvilTokens Toolkit (Mimecast)](https://www.mimecast.com/threat-intelligence-hub/oauth-device-code-phishing-campaigns/)
- [Microsoft: Hackers Steal Emails in Device Code Phishing Attacks (BleepingComputer)](https://www.bleepingcomputer.com/news/security/microsoft-hackers-steal-emails-in-device-code-phishing-attacks/)
- [The new hotness in phishing: device code attacks in M365 (TrustedSec)](https://trustedsec.com/blog/the-new-hotness-in-phishing-device-code-attacks-in-m365)
- [How to protect against Device Code Flow abuse (Storm-2372 attacks) and block the authentication flow](https://jeffreyappel.nl/how-to-protect-against-device-code-flow-abuse-storm-2372-attacks-and-block-the-authentication-flow/)
- [CIS Microsoft 365 Foundations 5.2.2.12: Ensure the device code sign-in flow is blocked](https://www.tenable.com/audits/items/CIS_Microsoft_365_Foundations_v6.0.1_L1_E5.audit:9033824c949b5560f26fa3d7bc1af197)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3086
