Summary Points
- Attackers exploited legitimate Microsoft 365 OAuth 2.0 device authorization to persuade victims into authenticating a malicious device, bypassing password theft.
- The campaign uses dynamic, disposable infrastructure, including DGA-like redirectors, spoofed company names, and active Cloudflare-hosted domains for ongoing credential harvesting and BEC impersonation.
- Over 290 malicious IoCs—including domains, subdomains, and IPs—have been identified, many of which remain active and have a history of malicious activity, signaling persistent threat persistence.
Threat, Attack Techniques, and Targets
ReversingLabs found a new device code phishing campaign that uses Microsoft 365’s OAuth 2.0 Device Authorization Grant flow. Instead of stealing passwords through fake login pages, attackers trick victims into completing a legitimate authentication process. This process grants access to an attacker-controlled device. The campaign includes hundreds of URLs identified as malicious network indicators. Many of these are part of a large, coordinated operation involving disposable infrastructure. The threats involve different patterns: random redirect hosts, hosts impersonating real companies, generic lures, and brand impersonation aimed at stealing credentials. Many malicious domains are active behind Cloudflare, with some using Google Cloud Platform and one registered domain now suspended. The campaign targets vulnerable users by posing as trusted entities or using unknown, random hosts to redirect victims.
Impact, Security Implications, and Remediation Guidance
This campaign poses significant security risks. Victims’ Microsoft 365 accounts are at risk of unauthorized access without traditional password theft. The attack’s use of legitimate OAuth flows makes detection more difficult. Many malicious domains and IP addresses are confirmed malicious or suspicious, and attackers may still be active. The campaign’s infrastructure includes typosquatting groups and malicious domain registrations, suggesting ongoing threats. Due to the evolving nature of such attacks, it is best to obtain remediation guidance from the relevant vendor or authority. Organizations should stay alert for suspicious URLs, monitor network traffic for unusual DNS activity, and strengthen user awareness. Immediate cooperation with Microsoft or cybersecurity professionals is recommended to review account activity and implement protective measures.
Discover More Technology Insights
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
