#Device Code phishing
10 stories taggedDevice Code phishing.

EvilTokens: the phishing kit that turned a smart-TV login trick into a mass account raid
Microsoft says a subscription phishing service broke into more than 12,000 mailboxes by abusing the sign-in flow built for printers and conference room screens.

GhostCode Phishing Kit Turns Microsoft's Own Login Flow Against You
A new tool called GhostCode abuses a legitimate Microsoft sign-in mechanism to steal account access, register attacker-controlled devices, and survive password resets, all in under 90 seconds.

Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms
A criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

Greatness Phishing Kit Adds a New Trick to Steal Logins Without Passwords
The rented phishing toolkit now abuses Microsoft's own login flow to walk around multi-factor authentication.

Russian hackers turn hotel Wi-Fi into a trap for Microsoft 365 logins
Microsoft has attributed the CaptiveCrunch campaign to Storm-2945, a sub-group of APT29, which has been poisoning hotel and conference Wi-Fi networks since at least May 2025 to steal corporate accounts using two newly identified malware families.

Device Code Phishing: The Login Trick That Blew Up in 2026
A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

Changing Your Password No Longer Kicks Hackers Out
A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

Helix: the new extortion crew phoning staff to raid SharePoint files
Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then pulls company documents from Microsoft SharePoint.

New Phishing Kit 'ARToken' Exposes Full Microsoft 365 Takeover Playbook
Cisco Talos researchers found more than 80 hidden commands inside a phishing service tied to the EvilTokens platform, including tools to steal Microsoft 365 logins, read mailboxes, and quietly hide attacker tracks.

Device Code Phishing Is Eating MFA. Behavioral Detection Is the Backstop.
Token theft and consent-grant abuse sidestep the second factor entirely. Defenders are leaning on anomaly detection because the login looks legitimate.