Tag

#Device Code phishing

10 stories taggedDevice Code phishing.

Illustration: a dimly lit modern conference room with a large wall-mounted video conferencing screen displaying an abstract
Identity & Access

EvilTokens: the phishing kit that turned a smart-TV login trick into a mass account raid

Microsoft says a subscription phishing service broke into more than 12,000 mailboxes by abusing the sign-in flow built for printers and conference room screens.

4 min read
A glowing blue padlock made of translucent code fragments slowly dissolving into streams of light against a dark server room background, with rows of blinking r
Identity & Access

GhostCode Phishing Kit Turns Microsoft's Own Login Flow Against You

A new tool called GhostCode abuses a legitimate Microsoft sign-in mechanism to steal account access, register attacker-controlled devices, and survive password resets, all in under 90 seconds.

4 min read
A Windows login screen being displayed on a corporate office computer, with device approval prompts visible and attacker control indicators in the system tray
Identity & Access

Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms

A criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

3 min read
A login screen on a computer monitor showing a Microsoft authentication interface with MFA prompts, while a shadow or overlay suggests an attacker's toolkit int
Identity & Access

Greatness Phishing Kit Adds a New Trick to Steal Logins Without Passwords

The rented phishing toolkit now abuses Microsoft's own login flow to walk around multi-factor authentication.

4 min read
A hotel lobby with Wi-Fi router and network infrastructure visible, guests at tables with laptops and phones connecting to wireless networks, login screens glow
Identity & Access

Russian hackers turn hotel Wi-Fi into a trap for Microsoft 365 logins

Microsoft has attributed the CaptiveCrunch campaign to Storm-2945, a sub-group of APT29, which has been poisoning hotel and conference Wi-Fi networks since at least May 2025 to steal corporate accounts using two newly identified malware families.

4 min read
A smart TV setup with a device code login screen displayed, corporate office network architecture visible in the background, breach pathways illustrated through
Identity & Access

Device Code Phishing: The Login Trick That Blew Up in 2026

A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

4 min read
A laptop screen showing an attacker's session still active in an email inbox even after a user has reset their password, demonstrating a persistent session toke
Identity & Access

Changing Your Password No Longer Kicks Hackers Out

A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

4 min read
Illustration: a dimly lit open-plan office at night, a desk phone glowing under a single lamp
Threat Intelligence

Helix: the new extortion crew phoning staff to raid SharePoint files

Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then pulls company documents from Microsoft SharePoint.

3 min read
Illustration: a dimly lit modern office desk at night, a laptop screen glowing with a generic blurred sign-in form
Identity & Access

New Phishing Kit 'ARToken' Exposes Full Microsoft 365 Takeover Playbook

Cisco Talos researchers found more than 80 hidden commands inside a phishing service tied to the EvilTokens platform, including tools to steal Microsoft 365 logins, read mailboxes, and quietly hide attacker tracks.

4 min read
Illustration: A dimly lit corporate office at night
Identity & Access

Device Code Phishing Is Eating MFA. Behavioral Detection Is the Backstop.

Token theft and consent-grant abuse sidestep the second factor entirely. Defenders are leaning on anomaly detection because the login looks legitimate.

3 min read
© 2026 Threat Vectr