Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Attackers Hijack Microsoft 365 Accounts Through OAuth Device Code Abuse Without Stealing Passwords

Recent analysis by ANY.RUN has revealed a significant increase in phishing campaigns exploiting Microsoft's OAuth Device Authorization Grant flow. Over 180 malicious URLs were detected in a week.

Recent analysis by ANY.RUN has revealed a significant increase in phishing campaigns exploiting Microsoft's OAuth Device Authorization Grant flow. Over 180 malicious URLs were detected in a week.

This phishing technique involves redirecting victims through legitimate Microsoft authentication pages, making it challenging for security operations centers (SOCs) to detect compromises in real time.

Originally designed for devices with limited input capabilities, the OAuth Device Code flow is now being exploited by attackers to bypass multi-factor authentication. This method has been repurposed to facilitate token-based account takeovers.

The attack begins when a threat actor initiates a Microsoft device authorization request, creating a user_code for the victim and a device_code for the attacker. Victims are directed to phishing pages that impersonate trusted brands like DocuSign, where they enter the verification code at microsoft[.]com/devicelogin . This action unknowingly authorizes a session for the attacker, granting them OAuth access and refresh tokens.

This method undermines traditional detection mechanisms by using legitimate Microsoft infrastructure and encrypted channels. Consequently, the phishing activity does not trigger standard filters or alerts.

Recent analysis by ANY.RUN has revealed a significant increase in phishing campaigns exploiting Microsoft's OAuth Device Authorization Grant flow.
Zachary Burns · Thehackingpost

Delayed detection: Compromise detection may only occur after suspicious activities are logged. Longer investigations: Analysts must trace token-based access paths rather than stolen credentials. Higher incident impact: Immediate access to Microsoft 365 resources is possible after token issuance. Persistent access: Attackers can maintain access using refresh tokens.

Beyond individual accounts, successful token issuance can lead to broader issues such as business email compromise and data exfiltration.

Sandbox Exposes the Hidden Attack Chain

ANY.RUN's Interactive Sandbox uses SSL decryption to uncover hidden functionalities in phishing pages. This process reveals network requests, scripts, and API endpoints involved in the phishing flow. Analysts can identify specific API calls and headers in HTTP requests to non-legitimate hosts, providing high-confidence indicators for campaign mapping.

Suricata IDS can detect these decrypted signals, turning encrypted sessions into actionable insights.

Advertisement

The following domains have been identified in this campaign:

singer-bodners-bau-at-s-account[.]workers[.]dev dibafef289[.]workers[.]dev ab-monvoisinproduction-com-s-account[.]workers[.]dev subzero908[.]workers[.]dev sandra-solorzano-duncanfamilyfarms-net-s-account[.]workers[.]dev tyler2miler-proton-me-s-account[.]workers[.]dev aarathe-ramraj-tipgroup-com-au-s-account[.]workers[.]dev rockymountainhi[.]workers[.]dev aiinnovationsfly[.]com astrolinktech[.]com

This campaign highlights the need for enhanced identity-layer visibility and encrypted traffic inspection as foundational requirements for modern SOC operations.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories