Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceidentity-authentication-vulnerabilitydata-exfiltration-methodbusiness-email-compromise

Phishing Attacks Exploiting OAuth Device Code Authorization for Microsoft 365 Account Takeover

Updated 1mo agoFirst seen Dec 18, 202517 sources

Threat actors are increasingly leveraging OAuth 2.0 device code authorization flows to compromise Microsoft 365 accounts through sophisticated phishing campaigns. Proofpoint researchers have observed both state-aligned and financially motivated groups using social engineering tactics to trick users into granting access to malicious applications, resulting in account takeovers, data exfiltration, and broader SaaS supply chain abuse. Attackers initiate these campaigns with phishing messages containing URLs or QR codes that, when followed, prompt users to authorize access for rogue applications, ultimately handing over OAuth tokens to the adversaries.

Industry analysis highlights that identity-first intrusions, including device code flow phishing and illicit OAuth consent, have driven significant data breaches and business email compromise incidents in 2025. Notable cases include the exploitation of connected apps to exfiltrate data from Salesforce tenants and major financial impacts on organizations such as Marks & Spencer. Security experts recommend enforcing phishing-resistant MFA, governing OAuth consent, and deprecating device code flows where feasible to mitigate these risks. Regulatory changes are also pushing organizations to strengthen identity and SaaS governance in response to these evolving threats.

Share:
Phishing Attacks Exploiting OAuth Device Code Authorization for Microsoft 365 Account Takeover
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Apr 1, 20263mo ago

Tycoon 2FA operators launch Microsoft 365 device code phishing campaign

In late April 2026, eSentire observed Tycoon 2FA operators repurpose their phishing-as-a-service kit to conduct OAuth device code phishing against Microsoft 365 users. The campaign used Trustifi tracking links and Cloudflare Workers redirects to drive victims to Microsoft's legitimate device login flow, issuing attacker-controlled OAuth tokens instead of stealing passwords directly.

Tycoon 2FA Operators Adopt OAuth Device Code Phishing | eSentire
Mar 1, 20264mo ago

Microsoft and Europol disrupt Tycoon 2FA infrastructure

In March 2026, Microsoft and Europol led a takedown targeting Tycoon 2FA infrastructure. Later reporting indicated the operators preserved their codebase and were able to restore operations quickly despite the disruption.

Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA - Cyber Security News
Jan 1, 20266mo ago

Device code phishing activity surges in 2026

Reporting in 2026 described a major increase in device code phishing attacks. Attackers were using the technique to steal access tokens and bypass standard access controls, making phishing operations more effective.

Analysing the rise in device code phishing attacks in 2026 - Infosec.Pub
Dec 16, 20256mo ago

Proofpoint publishes findings on widespread Microsoft 365 device code phishing

Proofpoint publicly reported that multiple state-aligned and financially motivated threat clusters were abusing the OAuth 2.0 device authorization grant to compromise Microsoft 365 accounts. The report highlighted tooling such as SquarePhish, SquarePhish2, and Graphish, and recommended restricting or blocking device code flow with Conditional Access and compliant-device requirements.

Oct 1, 20259mo ago

TA2723 adopts device code phishing with salary and document lures

In October 2025, financially motivated actor TA2723 began using device code phishing in campaigns themed around shared documents and salary-related files. Proofpoint assessed the actor likely used different tooling across campaign waves to scale the attacks.

Sep 1, 202510mo ago

Proofpoint observes broad surge in device code phishing activity

By September 2025, Proofpoint observed unusually widespread phishing campaigns abusing Microsoft's OAuth device code flow across multiple threat clusters. The campaigns targeted Microsoft 365 users and enabled account takeover, data theft, lateral movement, and persistence while bypassing MFA through legitimate Microsoft verification pages.

UNK_AcademicFlare starts rapport-based device code phishing campaign

By September 2025, the Russia-aligned cluster UNK_AcademicFlare was conducting device code phishing campaigns against targets in government, think tanks, higher education, and transportation in the U.S. and Europe. The group used compromised government and military email accounts plus Cloudflare Worker links spoofing OneDrive to lure victims into authorizing attacker access.

Jan 1, 20251y ago

State-aligned actors begin using Microsoft device code phishing

Proofpoint tracks state-aligned use of OAuth 2.0 device authorization grant phishing against Microsoft 365 accounts beginning in January 2025. The activity included Russia-aligned operators using the legitimate Microsoft device login flow to obtain access tokens and take over accounts.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

117 LINKEDOpen in app
Affected products
11 linked
DocusignAzureMicrosoft Entra IdMongodbExchange OnlineCloudflareVercelLinkedinAzure CliGoogle DriveMicrosoft Office
Organizations
89 linked
Microsoft CorporationProofpointGoogleLinkedinDocuSignAvastCyber Security NewsXCloudflareVolexitySecureworksHuntressSalesforceAlibaba CloudAmazon Web ServicesZscalereSentireTA2723UNK_AcademicFlareTrustifiTrend MicroAviraAkamai TechnologiesBarracuda NetworksPrivate Internet AccessCisco SystemsLevelBlueWindscribeZeroFoxipinfo.ioDigitaloceanExpressvpnSurfsharkPalo Alto NetworksMcafeeTenableSnowflakeForcepointEsetMimecastMongodbSekoiaAnthropicPush SecurityKasperskyFastlyVultrOVHcloudFortinetIvantiG DATA CyberDefenseOpenaiNetcraftPerplexityAPT29BroadcomGitHubCyberGhostAdobeQantasPraetorianVercelAny.RunOracleProtonNordvpnGroup-IBSophosBitdefenderMailchimpM247GraphishSquarePhishStorm-2372UTA0307UTA0304Cloudflare WorkerOxylabsHetzner Online GmbHBright DataLeaseWebMullvad VPNMarkMonitorDecodoCalyptSOAXBrandVerityIPBaseMicrosoft RiskIQ
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Phishing Attacks Exploiting OAuth Device Code Authorization for Microsoft 365 Account Takeover | Mallory