Researchers have identified an active device code phishing campaign/kit dubbed “GhostCode” that is distributed through web contact forms, whereby threat actors pose as a procurement officer of a legitimate business. Device code phishing kits abuse the OAuth 2.0 device authorization grant flow to gain access to Microsoft accounts https://www.esentire.com/blog/ghostcode-dissecting-a-novel-device-code-phishing-kit
Michael Jenkins, CTO at ThreatLocker provided the following comments:
“We’ve known for a while that attackers can get around MFA by stealing valid session tokens or sitting as an attacker-in-the-middle during MFA authentication. In this case, the victim completes a Microsoft authentication process but the attacker walks away with a valid token it can use to gain access. It’s another example of why MFA alone is no longer enough. Authentication should also verify that access is coming from an approved device so a stolen credential won’t work on an untrusted machine. Device identity needs to become another required layer of how we protect accounts online.”
Microsoft accounts are bane of my existence as account takeovers are common. One can hope that Microsoft does something about this so that changes.
Related
This entry was posted on September 16, 2026 at 4:20 pm and is filed under Commentary with tags Microsoft. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
New GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Take Over Accounts
Researchers have identified an active device code phishing campaign/kit dubbed “GhostCode” that is distributed through web contact forms, whereby threat actors pose as a procurement officer of a legitimate business. Device code phishing kits abuse the OAuth 2.0 device authorization grant flow to gain access to Microsoft accounts https://www.esentire.com/blog/ghostcode-dissecting-a-novel-device-code-phishing-kit
Michael Jenkins, CTO at ThreatLocker provided the following comments:
“We’ve known for a while that attackers can get around MFA by stealing valid session tokens or sitting as an attacker-in-the-middle during MFA authentication. In this case, the victim completes a Microsoft authentication process but the attacker walks away with a valid token it can use to gain access. It’s another example of why MFA alone is no longer enough. Authentication should also verify that access is coming from an approved device so a stolen credential won’t work on an untrusted machine. Device identity needs to become another required layer of how we protect accounts online.”
Microsoft accounts are bane of my existence as account takeovers are common. One can hope that Microsoft does something about this so that changes.
Share this:
Like this:
Related
This entry was posted on September 16, 2026 at 4:20 pm and is filed under Commentary with tags Microsoft. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.