WorkThe story, in brief

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

A new phishing kit called GhostCode is bypassing MFA to steal Microsoft 365 accounts — and the stolen credentials survive token revocation. Here's what defenders need to monitor.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

GhostCode exploits Microsoft's device-code OAuth flow to gain SSO-equivalent access to entire M365 environments. This is not a theoretical vulnerability — eSentire observed active campaigns establishing persistence through automated device enrollment and Primary Refresh Tokens that last 14 days by default. Practitioners managing Microsoft 365 deployments need detection rules and Conditional Access policies in place now.

The key facts

18 to know
  1. GhostCode phishing kit abuses Microsoft OAuth 2.0 device authorization grant flow

  2. Attackers obtained Primary Refresh Token (PRT) — 'one of the most powerful' credentials in M365 identity environment

  3. PRT persists 14 days by default and survives token revocation

  4. Nine API calls recorded over 78-second period post-authentication; three devices registered in automated sequence

  5. Intune enrollment survived token revocation until explicitly removed

  6. Attacker-controlled device achieved SSO-equivalent access to entire M365 environment

  7. Campaign involved social engineering via procurement officer impersonation and NDA-themed HTML files

  8. Defense recommendations: restrict device-code auth via Conditional Access, monitor Device Registration Service for multiple registrations from single non-interactive session, audit for python-requests user agent post-authentication

  9. Part of growing trend: prior device-code attacks include 'EvilTokens' PhaaS kit (Feb 2026) and multi-cluster state-sponsored activity (Dec 2026)

  10. GhostCode abuses Microsoft OAuth 2.0 device authorization flow to trick users into authorizing attacker devices

  11. Stolen Primary Refresh Token (PRT) grants SSO-equivalent access to entire M365 environment for 14 days by default

  12. Intune enrollment survives token revocation, providing persistence even after credential rotation

  13. Attackers registered 3 devices in 78 seconds post-authentication using automated API calls

  14. Campaign used social engineering (posing as procurement officers) + NDA-themed HTML lure to deliver phishing page

  15. Evasion techniques included HTML obfuscation, encrypted redirects, bot detection, Cloudflare Turnstile

  16. Defense recommendations: restrict device-code auth via Conditional Access, monitor Device Registration Service for bulk registrations, audit for python-requests user agent post-authentication

  17. Related campaigns: EvilTokens PhaaS kit (Feb 2026), December 2026 multi-cluster activity (financially motivated + state-sponsored actors)

  18. Identified by eSentire threat response unit in late August 2026

Go to the source

Computerworldcomputerworld.com

Publisher excerpt: Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026. The kit abuses…
Read original report
Back to today's editionMore work news

The wider picture

View all
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work01

AI in finance must be policed differently

As agentic AI enters financial services, regulators face a choice: adapt existing oversight or risk strangling innovation. This opinion argues for AI-native regulation rather than forcing agents into legacy compliance.

Financial Times Technology
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work02

US and China agree to dialogue on AI ahead of Trump-Xi meeting

Policy and regulatory coordination on AI between the world's two largest AI powers is emerging as a formal diplomatic track. This affects how practitioners navigate export controls, chip sanctions, and cross-border AI deployment.

Financial Times Technology
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work03

Trump says he’s planning to create an ‘AI Force’ and hire a new AI czar

Government AI strategy and personnel moves directly shape how AI companies navigate regulation, funding, and deployment priorities. A new White House AI czar and dedicated military-style AI unit signals serious federal commitment to AI competitiveness and could reshape vendor relationships, export controls, and domestic AI investment.

SiliconAngle