Home Cyber Security News Year-Long Microsoft Device Code Phishing Campaign Bypasses MFA and Claims 218 Victims

Year-Long Microsoft Device Code Phishing Campaign Bypasses MFA and Claims 218 Victims

0
Device-Code Phishing Bypasses MFA

A long-running Microsoft 365 device code phishing campaign has compromised at least 218 victims across multiple countries after abusing Microsoft’s legitimate OAuth Device Code Flow.

The operation, linked to a threat actor tracked as saroula01, remained active for more than a year and primarily targeted corporate users.

The campaign used a custom phishing framework known as black-queen, a modified Evilginx-based toolkit designed to steal Microsoft 365 OAuth tokens rather than passwords.

The technique bypasses multi-factor authentication because victims complete authentication on Microsoft’s legitimate device-login page, while attackers collect the resulting access and refresh tokens.

Device-Code Phishing Bypasses MFA

Microsoft’s Device Code Flow is intended for devices that cannot easily display a web browser, such as smart TVs, command-line tools, or Internet of Things devices.

Attackers weaponized this trusted workflow by generating a real Microsoft device code and showing it to targets on fake Microsoft Authenticator-themed pages.

Victims were instructed to visit Microsoft’s real microsoft.com/devicelogin page and enter the code to “validate MFA” or review a security alert.

Comments in Arabic from one of the script in the GitHub repository (Source: lexfo)

Because the Microsoft login page and code were legitimate, users could believe the request was safe even when checking the URL.

Once a victim entered the code and completed authentication, the attackers’ backend polled Microsoft’s token endpoint and obtained access tokens.

These tokens could provide access to Microsoft 365 resources without requiring the victim’s password or a separate MFA approval from the attacker.

Telemetry recovered from the campaign’s Telegram bot showed activity from June 18, 2025, through at least July 2, 2026.

Researchers identified 218 unique targets, including 94 corporate email addresses belonging to organizations across Australia, the United Kingdom, the United States, Switzerland, Spain, Poland, Canada, and other countries.

codemado’s Telegram profile (Source: lexfo)

The majority of victims used corporate domains, including those of organizations in professional services, legal, public sector, construction, automotive, recruitment, and small-business environments.

The campaign’s largest victim segment used .com domains, followed by .uk, .au, .pl, .es, .org, .net, .ch, and .ca addresses.

A deleted JSON file, recoverable from the phishing toolkit’s public Git history, allegedly contained 97 Microsoft OAuth token entries tied to three victims.

The tokens were configured with autoRefresh, enabling the tool to refresh active sessions in the background; some individual tokens had reportedly been refreshed as many as 25 times.

The infrastructure relied on the domain romnor.ca, hosted on an Azure virtual private server at 20.118.27.127.

Subdomains such as account.romnor.ca, briefing.romnor.ca, share.romnor.ca, download.romnor.ca, sign.romnor.ca, and team.romnor.ca were used to present different device code lure pages, lexfo said.

Indicators of Compromise

IOC TypeIndicatorDescription
Phishing domainromnor.caPrimary domain used for Microsoft Device Code phishing lures. paste.txt
Phishing URLaccount.romnor.caMicrosoft Authenticator-themed device code phishing page. paste.txt

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version