{"id":120350,"date":"2026-07-06T09:00:43","date_gmt":"2026-07-06T09:00:43","guid":{"rendered":"https:\/\/2.zoppoz.workers.dev:443\/https\/kasperskycontenthub.com\/securelist\/?p=120350"},"modified":"2026-07-17T13:49:18","modified_gmt":"2026-07-17T13:49:18","slug":"microsoft-device-code-phishing-attack","status":"publish","type":"post","link":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/microsoft-device-code-phishing-attack\/120350\/","title":{"rendered":"When checking the URL isn&#8217;t enough: a Device Code Phishing attack via a Microsoft website"},"content":{"rendered":"<p>One of the most common pieces of anti-phishing advice is to double-check the website&#8217;s domain name before providing your credentials. Typically, a fraudulent domain stands out to the trained eye, differing from the official URL by at least a few characters. Recently, however, we encountered a campaign where attackers instruct victims to input data directly into a legitimate, trusted corporate site: the <a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/learn.microsoft.com\/en-us\/entra\/identity-platform\/v2-oauth2-device-code\" target=\"_blank\" rel=\"noopener\">Microsoft Identity Platform<\/a>, which supports an OAuth 2.0 specification known as the <a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/learn.microsoft.com\/en-us\/entra\/identity-platform\/v2-oauth2-device-code\" target=\"_blank\" rel=\"noopener\">Device Authorization Grant<\/a>.<\/p>\n<p>This specific protocol extension was designed to simplify the login experience for smart TVs, IoT hardware, printers, and other input-constrained devices that lack a full browser or keyboard. It allows users to use a nearby smartphone or PC for authorizing these devices to access their accounts. To complete the process, the user enters a one-time code on a designated authentication page. The Microsoft Identity Platform returns this code along with a link to enter it in response to a request to <code>https:\/\/2.zoppoz.workers.dev:443\/https\/login.microsoftonline.com\/{tenant}\/oauth2\/v2.0\/devicecode<\/code>; hence, an attack scenario exploiting this mechanism is called Device Code Phishing.<br \/>\nIn this post, we break down how the Device Authorization Grant specification (also known as the Device Authorization Grant Flow or Device Code Flow) works, analyze real-world attacks leveraging this technology, and outline effective strategies to defend against Device Code Phishing.<\/p>\n<h2 id=\"core-steps-of-device-authorization-grant\">Core steps of Device Authorization Grant<\/h2>\n<p><strong>1. Requesting the authorization code<br \/>\n<\/strong><br \/>\nWhen a user launches an app on a client device, such as a streaming app on a Smart TV, the app detects that it is unauthenticated and sends a POST request to <code>https:\/\/2.zoppoz.workers.dev:443\/https\/login.microsoftonline.com\/{tenant}\/oauth2\/v2.0\/devicecode<\/code>. This request includes the <code>client_id<\/code> (the unique identifier of the app registered in Microsoft Entra ID \/ Azure AD) and the <code>scope<\/code> (the requested access permissions). In response, the application receives several parameters: <code>device_code<\/code> (a secret code for internal use), <code>user_code<\/code> (a short code displayed to the end-user), <code>verification_uri<\/code> (the login URL the user needs to visit), <code>expires_in<\/code> (the code&#8217;s lifespan), and <code>interval<\/code> (how frequently the app should poll the server).<\/p>\n<p><strong>2. Displaying the code to the user<\/strong><\/p>\n<p>The device displays both the <code>user_code<\/code> and the <code>verification_uri<\/code> to the user, instructing them to complete authentication on another device. For instance, a smart TV will display the code and URL\u00a0\u2014 often rendering the verification_uri as a QR code\u00a0\u2014 so the user can access it via their smartphone.<\/p>\n<p><strong>3. Entering the code and confirming access<br \/>\n<\/strong><br \/>\nBy scanning the QR code with a smartphone camera or manually typing out the address, the user navigates to the <code>verification_uri<\/code> (such as <a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/microsoft.com\/devicelogin\" target=\"_blank\" rel=\"noopener\">https:\/\/2.zoppoz.workers.dev:443\/https\/microsoft.com\/devicelogin<\/a>) and enters the <code>user_code<\/code><code>.<\/code><\/p>\n<p><strong>4. Polling the server<br \/>\n<\/strong><br \/>\nThe device (smart TV) begins polling the server to check the authorization status\u00a0\u2014 essentially verifying whether the user has approved the access request. It does this by sending a POST request to the token endpoint: <code>https:\/\/2.zoppoz.workers.dev:443\/https\/login.microsoftonline.com\/{tenant}\/oauth2\/v2.0\/token<\/code>. The request passes the grant_type parameter with the value <code>urn:ietf:params:oauth:grant-type:device_code<\/code>, indicating the use of the Device Authorization Grant method. This signals to the authorization server exactly which authentication method is being used to request access tokens. The server waits for the user to enter the <code>user_code<\/code> on their secondary device and approve access to their resources or data. Until that approval happens, the server responds with an error code like <code>authorization_pending<\/code> (keep waiting) or <code>slow_down<\/code> (reduce the polling frequency).<\/p>\n<p><strong>5. Issuing access tokens<\/strong><\/p>\n<p>Once the user successfully approves the application&#8217;s request, the server responds to the application by issuing an <code>access_token<\/code> (to access the data), a <code>refresh_token<\/code> (to renew access later), an <code>id_token<\/code> (containing user profile details like name and email), along with several other service parameters.<\/p>\n<p><strong>6. Automatic access renewal<\/strong><\/p>\n<p>The device (our smart TV) uses the <code>refresh_token<\/code> to silently renew the <code>access_token<\/code> without requiring any further user interaction. When the current <code>access_token<\/code> expires (typically after 1 hour), the device automatically sends a token refresh request containing the <code>refresh_token<\/code> to the token endpoint. It then receives a fresh pair of access and refresh tokens, ensuring the user remains authenticated seamlessly.<\/p>\n<p>While this workflow is truly convenient for input-constrained devices, attackers can abuse it to hijack user accounts and maintain persistent access for extended periods using the issued <code>refresh_token<\/code>. Let&#8217;s use a real-world example to break down this attack vector.<\/p>\n<h2 id=\"analysis-of-a-device-code-phishing-attack\">Analysis of a Device Code Phishing attack<\/h2>\n<div id=\"attachment_120373\" style=\"width: 1382px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1.jpeg\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120373\" class=\"size-full wp-image-120373\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1.jpeg\" alt=\"The phishing email\" width=\"1372\" height=\"402\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1.jpeg 1372w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1-300x88.jpeg 300w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1-1024x300.jpeg 1024w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1-768x225.jpeg 768w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1-1195x350.jpeg 1195w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1-740x217.jpeg 740w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1-956x280.jpeg 956w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204045\/device-code1-800x234.jpeg 800w\" sizes=\"auto, (max-width: 1372px) 100vw, 1372px\" \/><\/a><p id=\"caption-attachment-120373\" class=\"wp-caption-text\">The phishing email<\/p><\/div>\n<p>In a phishing campaign we observed spanning from early April to mid-May 2026, the initial email was styled as a notice from a law firm. Attached to the email was a password-protected PDF file.<\/p>\n<p><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204118\/device-code2.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-120374\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204118\/device-code2.png\" alt=\"\" width=\"917\" height=\"709\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204118\/device-code2.png 917w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204118\/device-code2-300x232.png 300w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204118\/device-code2-768x594.png 768w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204118\/device-code2-453x350.png 453w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204118\/device-code2-740x572.png 740w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204118\/device-code2-362x280.png 362w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204118\/device-code2-800x619.png 800w\" sizes=\"auto, (max-width: 917px) 100vw, 917px\" \/><\/a><\/p>\n<p>Once the victim opened the PDF and entered the password, they were presented with a landing page listing several documents. However, viewing these documents required clicking a provided link.<\/p>\n<div id=\"attachment_120375\" style=\"width: 661px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204146\/device-code3.jpeg\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120375\" class=\"size-full wp-image-120375\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204146\/device-code3.jpeg\" alt=\"PDF file with a malicious link\" width=\"651\" height=\"709\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204146\/device-code3.jpeg 651w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204146\/device-code3-275x300.jpeg 275w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204146\/device-code3-321x350.jpeg 321w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204146\/device-code3-257x280.jpeg 257w\" sizes=\"auto, (max-width: 651px) 100vw, 651px\" \/><\/a><p id=\"caption-attachment-120375\" class=\"wp-caption-text\">PDF file with a malicious link<\/p><\/div>\n<p>A close look at the target URL reveals that instead of pointing to a typical, easily recognizable phishing domain, it actually points to a legitimate Microsoft address. However, the URL parameters are configured to redirect the user to a phishing resource.<\/p>\n<p><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204242\/device-code4.jpeg\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-120376\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204242\/device-code4.jpeg\" alt=\"\" width=\"1430\" height=\"292\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204242\/device-code4.jpeg 1430w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204242\/device-code4-300x61.jpeg 300w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204242\/device-code4-1024x209.jpeg 1024w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204242\/device-code4-768x157.jpeg 768w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204242\/device-code4-740x151.jpeg 740w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204242\/device-code4-1371x280.jpeg 1371w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204242\/device-code4-800x163.jpeg 800w\" sizes=\"auto, (max-width: 1430px) 100vw, 1430px\" \/><\/a><\/p>\n<p>The link within the document does not keep the user on the Microsoft platform; instead, it immediately redirects them to a phishing page designed to mimic a corporate legal portal.<\/p>\n<div id=\"attachment_120600\" style=\"width: 925px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171017\/code-phishing-attack5.jpg\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120600\" class=\"size-full wp-image-120600\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171017\/code-phishing-attack5.jpg\" alt=\"\" width=\"915\" height=\"672\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171017\/code-phishing-attack5.jpg 915w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171017\/code-phishing-attack5-300x220.jpg 300w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171017\/code-phishing-attack5-768x564.jpg 768w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171017\/code-phishing-attack5-477x350.jpg 477w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171017\/code-phishing-attack5-740x543.jpg 740w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171017\/code-phishing-attack5-381x280.jpg 381w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171017\/code-phishing-attack5-800x588.jpg 800w\" sizes=\"auto, (max-width: 915px) 100vw, 915px\" \/><\/a><p id=\"caption-attachment-120600\" class=\"wp-caption-text\">The phishing page<\/p><\/div>\n<p>Interestingly, the landing page featured multiple CAPTCHAs, presumably deployed to filter out security crawlers. Once past these hurdles, the user was routed to a final page that instructed them to copy a one-time code. This code was the user_code that the attacker&#8217;s server-side application had already fetched by querying <code>https:\/\/2.zoppoz.workers.dev:443\/https\/login.microsoftonline.com\/{tenant}\/oauth2\/v2.0\/devicecode<\/code>, as detailed in the workflow above.<\/p>\n<div id=\"attachment_120602\" style=\"width: 753px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171434\/code-phishing-attack6.jpg\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120602\" class=\"wp-image-120602 size-full\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171434\/code-phishing-attack6.jpg\" alt=\"\" width=\"743\" height=\"577\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171434\/code-phishing-attack6.jpg 743w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171434\/code-phishing-attack6-300x233.jpg 300w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171434\/code-phishing-attack6-451x350.jpg 451w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171434\/code-phishing-attack6-740x575.jpg 740w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171434\/code-phishing-attack6-361x280.jpg 361w\" sizes=\"auto, (max-width: 743px) 100vw, 743px\" \/><\/a><p id=\"caption-attachment-120602\" class=\"wp-caption-text\">The one-time code<\/p><\/div>\n<div class=\"mceTemp\">\n<p>The one-time codeClicking the displayed one-time code automatically copied it to the clipboard while simultaneously redirecting the user to Microsoft&#8217;s actual, legitimate authentication page (<code>verification_uri<\/code>), where they were prompted to paste and enter the code.<\/p>\n<div id=\"attachment_120379\" style=\"width: 668px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204418\/device-code7.jpeg\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120379\" class=\"size-full wp-image-120379\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204418\/device-code7.jpeg\" alt=\"Official Microsoft authentication page\" width=\"658\" height=\"499\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204418\/device-code7.jpeg 658w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204418\/device-code7-300x228.jpeg 300w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204418\/device-code7-462x350.jpeg 462w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204418\/device-code7-369x280.jpeg 369w\" sizes=\"auto, (max-width: 658px) 100vw, 658px\" \/><\/a><p id=\"caption-attachment-120379\" class=\"wp-caption-text\">Official Microsoft authentication page<\/p><\/div>\n<p>Once the user entered the code, it kicked off the Device Authorization Grant flow described earlier. The unsuspecting victim then completed the full MFA process directly on Microsoft&#8217;s official page. As soon as authentication succeeded, the attacker harvested the session&#8217;s access_token, refresh_token, and id_token. This enabled them to read and send emails from the victim&#8217;s mailbox, exfiltrate files from OneDrive, and access Teams conversations.<\/p>\n<h2 id=\"adaptation-of-the-attack-method\">Adaptation of the attack method<\/h2>\n<p>This phishing campaign was limited in scope and spanned slightly more than a month. However, the threat actor continues to actively leverage this method, adapting it to target specific geographic regions. We&#8217;ve recently detected slightly modified Device Code Phishing campaigns shifting their focus toward users in Brazil, among others.<\/p>\n<div id=\"attachment_120380\" style=\"width: 1104px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8.jpeg\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120380\" class=\"size-full wp-image-120380\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8.jpeg\" alt=\"The Brazilian phishing variant\" width=\"1094\" height=\"560\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8.jpeg 1094w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8-300x154.jpeg 300w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8-1024x524.jpeg 1024w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8-768x393.jpeg 768w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8-684x350.jpeg 684w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8-740x379.jpeg 740w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8-547x280.jpeg 547w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204458\/device-code8-800x410.jpeg 800w\" sizes=\"auto, (max-width: 1094px) 100vw, 1094px\" \/><\/a><p id=\"caption-attachment-120380\" class=\"wp-caption-text\">The Brazilian phishing variant<\/p><\/div>\n<details>\n<summary>Translated from Portuguese:<\/summary>\n<p><em>&#8220;Hello!<\/em><br \/>\n<em>Your order has just been processed, and the confirmation has been sent to you in PDF format. Please see the details below.<\/em><br \/>\n<em>OPEN \/ DOWNLOAD PDF<\/em><br \/>\n<em>A new quote is attached to this email.<\/em><br \/>\n<em>Please let me know if you need any further assistance.&#8221;<\/em><\/p>\n<\/details>\n<p>\u00a0 Unlike the previous campaign, this email did not include a malicious PDF attachment. Instead, it embedded a link pointing to cacoo.com, a legitimate online diagramming platform owned by Nulab. Just as before, this trusted domain served as an open redirect to steer the user toward the phishing infrastructure.<\/p>\n<div class=\"mceTemp\">\n<p>The proxy link routes through the legitimate Cacoo.com domain before redirecting to the phishing site<\/p>\n<details>\n<summary>Translated from Portuguese:<\/summary>\n<p><em>Request confirmation<\/em><br \/>\n<em>Status Code = Success<\/em><br \/>\n<em>DOWNLOAD OR VIEW THE DOCUMENT<\/em><br \/>\n<em>Important note: Log in to the account that received this message to securely authenticate the document.<\/em><\/p>\n<\/details>\n<p>Clicking the link routed the user back to the familiar landing page displaying the one-time code.<\/p>\n<div id=\"attachment_120604\" style=\"width: 726px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171628\/code-phishing-attack10-2.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120604\" class=\"size-full wp-image-120604\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171628\/code-phishing-attack10-2.png\" alt=\"\" width=\"716\" height=\"593\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171628\/code-phishing-attack10-2.png 716w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171628\/code-phishing-attack10-2-300x248.png 300w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171628\/code-phishing-attack10-2-423x350.png 423w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03171628\/code-phishing-attack10-2-338x280.png 338w\" sizes=\"auto, (max-width: 716px) 100vw, 716px\" \/><\/a><p id=\"caption-attachment-120604\" class=\"wp-caption-text\">Landing page displaying the code<\/p><\/div>\n<p>From there, the potential victim was once again redirected to the official Microsoft portal to complete the Device Authorization Grant authentication process.<\/p>\n<div id=\"attachment_120604-2\" style=\"width: 745px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204741\/device-code11.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120604-2\" class=\"size-full wp-image-120383\" src=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204741\/device-code11.png\" alt=\"Official Microsoft page prompting for the user code\" width=\"735\" height=\"613\" srcset=\"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204741\/device-code11.png 735w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204741\/device-code11-300x250.png 300w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204741\/device-code11-420x350.png 420w, https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/24204741\/device-code11-336x280.png 336w\" sizes=\"auto, (max-width: 735px) 100vw, 735px\" \/><\/a><p id=\"caption-attachment-120604-2\" class=\"wp-caption-text\">Official Microsoft page prompting for the user code<\/p><\/div>\n<h2 id=\"how-to-defend-against-device-code-phishing-attacks\">How to defend against Device Code Phishing attacks<\/h2>\n<p>As our research demonstrates, threat actors don&#8217;t always rely on harvesting credentials or deploying malware to access sensitive data\u00a0\u2014 they can just as easily weaponize legitimate tools. Therefore, users must exercise vigilance not only when visiting suspicious sites, but also when navigating official platforms like Microsoft or Cacoo.com.<\/p>\n<p>Recommendations for users<\/p>\n<ul>\n<li>If you did not personally initiate a login request on an external device using the Microsoft Device Authorization Grant, do not approve the authorization request.<\/li>\n<li>Never enter an authorization code received via unexpected emails or messages, even if the provided link points directly to an official Microsoft domain.<\/li>\n<li>Threat actors frequently leverage open redirects on legitimate domains, appending parameters like <code>redirect_uri<\/code>, <code>return_url<\/code>, or next after the question mark (?) to point to a malicious destination. Before clicking any link, hover your cursor over it to inspect both the primary domain and any suspicious redirect parameters. Once the page loads, verify that the final URL actually matches the expected asset \u2014 this is the absolute minimum requirement before entering corporate credentials.<\/li>\n<\/ul>\n<p>We strongly advise enterprise teams to evaluate the business necessity of the Device Code Flow within their corporate infrastructure. If this authentication mechanism is not required for daily operations, it should be disabled globally via Conditional Access policies within Microsoft Entra ID. Additionally, security teams should set up dedicated monitoring for <code>DeviceCodeSignIn<\/code> events, strictly e nforce device compliance states, and configure alerts for anomalous sign-in behavior originating from unusual locations.<\/p>\n<p>To establish a comprehensive defense against Device Code Phishing attacks, organizations should deploy robust email security solutions capable of securing both <a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/www.kaspersky.com\/enterprise-security\/mail-server-security?icid=kl-ru_sl_post-ksms_sm-team_28043507eef1c27b\" target=\"_blank\" rel=\"noopener\">corporate<\/a> and <a href=\"https:\/\/2.zoppoz.workers.dev:443\/https\/www.kaspersky.com\/premium?icid=kl-ru_sl_post-kprem_sm-team_0239623e36ba5b4f\" target=\"_blank\" rel=\"noopener\">personal<\/a> messages.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.<\/p>\n","protected":false},"author":[412],"featured_media":120598,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6061,915],"tags":[33,723,1053,4540,6229],"threat-category":[14],"coauthors":[1110],"class_list":["post-120350","post","type-post","status-publish","format-standard","has-post-thumbnail","category-great-research","category-spam-and-phishing","tag-microsoft","tag-phishing","tag-phishing-websites","tag-qr-codes","tag-oauth","threat-category-spam-and-phishing","securelist-post"],"acf":[],"banners":"","hreflang":[{"hreflang":"x-default","url":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/microsoft-device-code-phishing-attack\/120350\/"},{"hreflang":"ru","url":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.ru\/microsoft-device-code-phishing-attack\/116061\/"},{"hreflang":"es","url":"https:\/\/2.zoppoz.workers.dev:443\/https\/latam.securelist.com\/microsoft-device-code-phishing-attack\/101133\/"},{"hreflang":"pt-br","url":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com.br\/microsoft-device-code-phishing-attack\/1700\/"}],"featured_image":"https:\/\/2.zoppoz.workers.dev:443\/https\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/07\/03170147\/Device-Code-Phishing-pingpongsuperman_A_fisherman_hacker_is_fishing_using_a_large_TV_261a6841-d900-4140-bffd-0f2f596e9977-scaled.jpg","_links":{"self":[{"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/posts\/120350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/users\/412"}],"replies":[{"embeddable":true,"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/comments?post=120350"}],"version-history":[{"count":19,"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/posts\/120350\/revisions"}],"predecessor-version":[{"id":120717,"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/posts\/120350\/revisions\/120717"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/media\/120598"}],"wp:attachment":[{"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/media?parent=120350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/categories?post=120350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/tags?post=120350"},{"taxonomy":"threat-category","embeddable":true,"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/threat-category?post=120350"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/wp-json\/wp\/v2\/coauthors?post=120350"}],"curies":[{"name":"wp","href":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.w.org\/{rel}","templated":true}]}}