Ongoing Campaign Targets Microsoft 365 to Steal OAuth Tokens for Persistent Access
A phishing campaign has been identified exploiting Microsoft’s OAuth 2.0 Device Authorization Grant flow to gain unauthorized and persistent access to Microsoft 365 accounts. This campaign, active since December 2025, primarily targets professionals and…
A phishing campaign has been identified exploiting Microsoft’s OAuth 2.0 Device Authorization Grant flow to gain unauthorized and persistent access to Microsoft 365 accounts. This campaign, active since December 2025, primarily targets professionals and enterprises in North America, with 44% of victims located in the United States. Impacted sectors include technology, manufacturing, and financial services.
The attack circumvents traditional credential theft and multi-factor authentication (MFA) by manipulating the authentication flow. Victims unknowingly assist attackers in obtaining valid OAuth access and refresh tokens, granting full access to corporate Microsoft 365 environments.
The attack involves registering a malicious application on Microsoft’s OAuth platform to generate a unique device code. This code is embedded in a phishing email sent to targeted individuals. The email employs social engineering tactics, such as fake payment notifications, to prompt recipients to click on an embedded link.
Victims who follow the link are directed to an attacker-controlled landing page that mimics legitimacy. They are instructed to visit Microsoft’s official portal at microsoft.com/devicelogin and enter the provided device code as part of a “secure authentication” process. Upon entering the code and completing the authentication process, including MFA, Microsoft issues OAuth tokens that provide the attacker with full account access.
Impacted sectors include technology, manufacturing, and financial services.
These tokens enable the attacker to perform actions such as reading and sending emails, accessing OneDrive and SharePoint files, scheduling meetings, and executing administrative tasks without re-entering credentials or triggering MFA challenges.
The persistence of this campaign is particularly damaging, as refresh tokens allow attackers to generate new access tokens continuously. This keeps a backdoor open to the victim’s Microsoft 365 account for as long as the tokens remain valid, posing risks to corporate data and sensitive communications even after password resets or MFA reconfigurations.
Organizations are advised to audit all recently consented OAuth applications in their Microsoft 365 environment and identify suspicious apps not explicitly approved by users. Additionally, IT teams should monitor email gateways and logs for recurring sender patterns or subject lines indicating phishing attempts.
Security measures include disabling device code flow for nonessential use through Conditional Access policies and educating employees about OAuth-based phishing. As attackers increasingly exploit trusted authentication flows, defense strategies must evolve beyond password and MFA protections. Continuous monitoring and strict application consent policies are essential to prevent OAuth token abuse within enterprise ecosystems.
Based on reporting by GBHackers.
