Attackers Hijack Microsoft 365 Accounts Through OAuth Device Code Abuse Without Stealing Passwords
Recent analysis by ANY.RUN has revealed a significant increase in phishing campaigns exploiting Microsoft's OAuth Device Authorization Grant flow. Over 180 malicious URLs were detected in a week.
Recent analysis by ANY.RUN has revealed a significant increase in phishing campaigns exploiting Microsoft's OAuth Device Authorization Grant flow. Over 180 malicious URLs were detected in a week.
This phishing technique involves redirecting victims through legitimate Microsoft authentication pages, making it challenging for security operations centers (SOCs) to detect compromises in real time.
Originally designed for devices with limited input capabilities, the OAuth Device Code flow is now being exploited by attackers to bypass multi-factor authentication. This method has been repurposed to facilitate token-based account takeovers.
The attack begins when a threat actor initiates a Microsoft device authorization request, creating a user_code for the victim and a device_code for the attacker. Victims are directed to phishing pages that impersonate trusted brands like DocuSign, where they enter the verification code at microsoft[.]com/devicelogin . This action unknowingly authorizes a session for the attacker, granting them OAuth access and refresh tokens.
This method undermines traditional detection mechanisms by using legitimate Microsoft infrastructure and encrypted channels. Consequently, the phishing activity does not trigger standard filters or alerts.
Recent analysis by ANY.RUN has revealed a significant increase in phishing campaigns exploiting Microsoft's OAuth Device Authorization Grant flow.
Delayed detection: Compromise detection may only occur after suspicious activities are logged. Longer investigations: Analysts must trace token-based access paths rather than stolen credentials. Higher incident impact: Immediate access to Microsoft 365 resources is possible after token issuance. Persistent access: Attackers can maintain access using refresh tokens.
Beyond individual accounts, successful token issuance can lead to broader issues such as business email compromise and data exfiltration.
Sandbox Exposes the Hidden Attack Chain
ANY.RUN's Interactive Sandbox uses SSL decryption to uncover hidden functionalities in phishing pages. This process reveals network requests, scripts, and API endpoints involved in the phishing flow. Analysts can identify specific API calls and headers in HTTP requests to non-legitimate hosts, providing high-confidence indicators for campaign mapping.
Suricata IDS can detect these decrypted signals, turning encrypted sessions into actionable insights.
The following domains have been identified in this campaign:
singer-bodners-bau-at-s-account[.]workers[.]dev dibafef289[.]workers[.]dev ab-monvoisinproduction-com-s-account[.]workers[.]dev subzero908[.]workers[.]dev sandra-solorzano-duncanfamilyfarms-net-s-account[.]workers[.]dev tyler2miler-proton-me-s-account[.]workers[.]dev aarathe-ramraj-tipgroup-com-au-s-account[.]workers[.]dev rockymountainhi[.]workers[.]dev aiinnovationsfly[.]com astrolinktech[.]com
This campaign highlights the need for enhanced identity-layer visibility and encrypted traffic inspection as foundational requirements for modern SOC operations.
Based on reporting by Cyber Security News.
