← Back to feed
PhishingEmerging1 sourceSep 18, 2026 · 15:18via CSO Online

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

Brief

Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026.

The kit abuses Microsoft’s OAuth 2. 0 device authorization grant flow, a legitimate mechanism designed to enable authentication from IoT devices, smart TVs, printers, or other devices that cannot easily support a conventional browser-based login. The technique, known as device-code phishing , has been seen in other attacks before.

As part of the flow, the device displays a code for the user to enters in a browser on another device to complete authentication.

Read more on CSO Online→