Microsoft Entra Accounts Targeted in Device Code Vishing Attacks: A Growing Threat
Hackers are employing a sophisticated technique to compromise Microsoft Entra accounts, combining device code phishing and voice phishing (vishing) to exploit the OAuth 2.0 Device Authorization flow. This method is particularly insidious as it leverages legitimate Microsoft OAuth client IDs and device authorization flows, making it harder for victims to detect the attack.
Instead of traditional phishing sites, attackers use legitimate Microsoft login forms and standard device code authentication workflows to breach corporate accounts. This approach provides valid authentication tokens, allowing access to the victim's account without stealing passwords or intercepting multi-factor authentication codes.
The ShinyHunters extortion gang is believed to be behind these attacks, according to a source speaking to BleepingComputer, a claim later confirmed by the threat actors themselves. ShinyHunters has a history of vishing attacks, previously targeting Okta and Microsoft Entra SSO accounts for data theft.
Device code social engineering attacks are becoming more prevalent, no longer requiring attacker-controlled infrastructure. Attackers use open-source tools to generate device codes and user codes, which they then share with targets. The goal is to convince employees to enter these codes on the Microsoft device authentication page, microsoft.com/devicelogin.
Once the targeted person authenticates, the attackers can retrieve the refresh token and exchange it for access tokens, granting them access to the employee's Microsoft services without re-authenticating via multi-factor authentication. This enables the theft of corporate data for extortion.
KnowBe4 Threat Labs has also uncovered a campaign using traditional phishing emails and websites to deliver device code attacks, relying on social engineering lures like fake payment prompts and document-sharing alerts. Microsoft 365 account holders are advised to block malicious domains, audit OAuth app consents, and review Azure AD sign-in logs for device code authentication events.
Administrators are recommended to disable the device code flow when not required and enforce conditional access policies. Device code phishing is not new, with Russian hackers targeting Microsoft 365 accounts using this method in 2025, and similar attacks reported by ProofPoint in December of the same year.
As IT infrastructure becomes more complex, the need for robust security measures becomes increasingly vital. Modern IT infrastructure moves faster than manual workflows can handle, making it essential to stay vigilant against evolving cyber threats.