GhostCode attackers abuse device codes to take over Microsoft 365 accounts
Brief
Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026.
The kit abuses Microsoft’s OAuth 2. 0 device authorization grant flow, a legitimate mechanism designed to enable authentication from IoT devices, smart TVs, printers, or other devices that cannot easily support a conventional browser-based login. The technique, known as device-code phishing , has been seen in other attacks before.
As part of the flow, the device displays a code for the user to enters in a browser on another device to complete authentication.
