New GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Take Over Accounts 

Researchers have identified an active device code phishing campaign/kit dubbed “GhostCode” that is distributed through web contact forms, whereby threat actors pose as a procurement officer of a legitimate business. Device code phishing kits abuse the OAuth 2.0 device authorization grant flow to gain access to Microsoft accounts https://www.esentire.com/blog/ghostcode-dissecting-a-novel-device-code-phishing-kit

Michael Jenkins, CTO at  ThreatLocker provided the following comments:

“We’ve known for a while that attackers can get around MFA by stealing valid session tokens or sitting as an attacker-in-the-middle during MFA authentication. In this case, the victim completes a Microsoft authentication process but the attacker walks away with a valid token it can use to gain access. It’s another example of why MFA alone is no longer enough. Authentication should also verify that access is coming from an approved device so a stolen credential won’t work on an untrusted machine. Device identity needs to become another required layer of how we protect accounts online.”

Microsoft accounts are bane of my existence as account takeovers are common. One can hope that Microsoft does something about this so that changes.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading