GhostCode Phishing Kit Targets Microsoft Accounts Through OAuth Device Codes
A new phishing campaign is exploiting Microsoft’s device authentication process to hijack accounts, giving attackers a way to bypass traditional multifactor authentication protections.
Researchers at eSentire have named the phishing kit “GhostCode.” The campaign begins when attackers submit messages through corporate website contact forms while impersonating procurement representatives from legitimate organizations.
These messages are designed to establish trust and steer employees into a fraudulent authentication sequence. Instead of attempting to capture a password directly, GhostCode abuses the OAuth 2.0 device authorization grant used by Microsoft services.
Device authorization allows users to sign in on a separate device by entering a temporary code. In the GhostCode attack, the victim completes a real Microsoft authentication process using a code controlled by the attacker. Once authentication succeeds, the threat actor receives a valid access token that can be used to enter the victim’s account.
The method is particularly dangerous because users may see authentic Microsoft login pages and complete their normal MFA challenge. That makes the activity more difficult to recognize than a conventional credential-harvesting page.
Michael Jenkins, CTO at ThreatLocker, said the campaign demonstrates why organizations can no longer treat MFA as a complete defense against account takeover.
“We’ve known for a while that attackers can get around MFA by stealing valid session tokens or sitting as an attacker-in-the-middle during MFA authentication. In this case, the victim completes a Microsoft authentication process but the attacker walks away with a valid token it can use to gain access. It’s another example of why MFA alone is no longer enough. Authentication should also verify that access is coming from an approved device so a stolen credential won't work on an untrusted machine. Device identity needs to become another required layer of how we protect accounts online.”
GhostCode reinforces a broader shift in phishing operations. Attackers are increasingly targeting authentication workflows and session tokens instead of passwords alone.
Security teams should scrutinize unsolicited procurement inquiries, monitor unusual device-code authentication attempts and restrict access from unmanaged endpoints. Conditional access policies, device verification and phishing-resistant authentication can provide additional protection when valid tokens fall into the wrong hands.


