GhostCode attackers abuse device codes to take over Microsoft 365 accounts

Summary

A new phishing kit called GhostCode is exploiting Microsoft's OAuth 2.0 device authorization flow to gain unauthorized access to Microsoft 365 accounts. Attackers trick victims into entering a device code on a legitimate Microsoft authentication page, which allows them to obtain authentication tokens and register their own devices to gain persistence.

IFF Assessment

FOE

This article details a new phishing technique that allows attackers to compromise Microsoft 365 accounts, representing a threat to defenders.

Defender Context

Defenders should be aware of the GhostCode phishing kit and the abuse of the OAuth 2.0 device authorization flow. This technique allows attackers to bypass traditional security measures by leveraging a legitimate authentication mechanism, emphasizing the need for user education on phishing tactics and vigilance against unusual login prompts.

Read Full Story →