GhostCode attackers abuse device codes to take over Microsoft 365 accounts
eSentire researchers found the GhostCode phishing kit abusing Microsoft's legitimate OAuth device authorization flow to steal Microsoft 365 access tokens. The attack registers devices in Intune and obtains a Primary Refresh Token with a 14-day lifetime, enabling persistent access.
- GhostCode impersonates a device and obtains an OAuth Microsoft authorization code
- 9 API calls and registration of three devices recorded in 78 seconds
- Third device enrolled in Intune and persists even after token revocation
- PRT grants SSO access to the entire M365 environment for 14 days by default
Read next
Security