.webp)
GhostCode Abuses Microsoft Device Codes to Steal M365 Tokens and Register Rogue Devices
eSentire’s Threat Response Unit (TRU) has uncovered a previously undocumented device-code phishing kit, dubbed “GhostCode,” that abuses Microsoft’s OAuth 2.0 device authorization grant flow to hijack M365 accounts, mint Primary Refresh Tokens (PRTs), and silently enroll rogue devices all within roughly 78 seconds of a victim completing MFA. GhostCode M365 Tokens The campaign, first observed […]
The post GhostCode Abuses Microsoft Device Codes to Steal M365 Tokens and Register Rogue Devices appeared first on Cyber Security News.