#Device Code phishing
9 stories taggedDevice Code phishing.

Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms
A new criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

Greatness Phishing Kit Adds a New Trick to Steal Logins Without Passwords
The rented phishing toolkit now abuses Microsoft's own login flow to walk around multi-factor authentication.

Russian hackers turn hotel Wi-Fi into a trap for Microsoft 365 logins
Microsoft says APT29 sub-group Storm-2945 has been hijacking guest Wi-Fi at hotels and conference centres since May, planting two new malware families to steal corporate accounts.

Device Code Phishing: The Login Trick That Blew Up in 2026
A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

Changing Your Password No Longer Kicks Hackers Out
A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

Forg365: A $400-a-Month Kit That Hijacks Microsoft 365 Logins
A new subscription phishing service uses device codes, session theft and AI-written lures to break into corporate email accounts.

Helix: the new extortion crew phoning staff to raid SharePoint files
Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then hoovers up company documents from Microsoft SharePoint.

New Phishing Kit 'ARToken' Exposes Full Microsoft 365 Takeover Playbook
Cisco Talos researchers found more than 80 hidden commands inside a phishing service tied to the EvilTokens platform — including tools to steal Microsoft 365 logins, read mailboxes, and quietly hide their tracks.

Device Code Phishing Is Eating MFA. Behavioral Detection Is the Backstop.
Token theft and consent-grant abuse sidestep the second factor entirely. Defenders are leaning on anomaly detection because the login looks legitimate.