Home Cyber Security News Hackers Abuse Microsoft Device Code Flow to Bypass MFA and Hijack Microsoft...

Hackers Abuse Microsoft Device Code Flow to Bypass MFA and Hijack Microsoft 365 Accounts

0
MFA Bypass Device Flow

Hackers are increasingly abusing Microsoft’s legitimate device code flow to bypass multi-factor authentication (MFA) and hijack Microsoft 365 accounts, turning trusted identity controls into a covert account takeover vector.

This article explains how the attack works, why it reliably bypasses MFA, and what defenders can do to detect and block it.

The OAuth 2.0 Device Authorization Grant (device code flow) was designed for “input-limited” devices that cannot easily show a login page or accept keyboard input, such as smart TVs, room systems, and certain IoT endpoints.

In a normal scenario, the device requests a short code, the user visits a Microsoft sign-in URL on a separate trusted device, enters the code, completes MFA, and Microsoft issues tokens back to the original device that requested access.

MFA Bypass Device Flow

In device code phishing, attackers impersonate that input-limited device and initiate a legitimate device-code request against Microsoft Entra ID, obtaining a valid one-time code tied to their infrastructure.

They then deliver this code to victims via convincing lures document-sharing emails, QR codes, or “account verification” prompts directing users to the real Microsoft sign-in page to enter the attacker’s code and complete MFA as usual.

The same flow, abused. The attacker requests the code and receives the tokens, while the victim performs the sign-in (Source: trendmicro)

Because the entire flow runs on a genuine Microsoft page with valid MFA, the resulting OAuth access and refresh tokens are issued to the attacker’s system, not the victim’s, effectively turning the victim’s trusted device into a credential laundering service.

Once the attacker has tokens, they can log into Microsoft 365 services such as Outlook, OneDrive, SharePoint, and Teams without ever stealing or reusing the password.

Crucially, those tokens often remain valid even after password resets, allowing long-lived persistence until identity controls explicitly revoke the tokens or sessions.

The delivery chain we observed. Each hop uses a trusted or throwaway service to stay ahead of email and URL filtering (Source: trendmicro)

Recent campaigns against Microsoft 365 tenants start with multi-step social engineering instead of a single crude phishing email, making the device code request feel like part of a normal business workflow.

Attackers chain trusted services Google Sites, compromised corporate redirects, and cloud workers to host lures and verification pages, then present a “verification code” with instructions to enter it at Microsoft’s official device login portal, ensuring that email filters and URL reputation systems are less likely to block the sequence, trendmicro said.

Indicators of Compromise

TypeIndicator
Sender / impersonation domainsrlcounsel[.]com
Sender / impersonation domainscholaw-kr[.]co
Lure pages (trusted host)sites.google[.]com/view/businessprofileoverview
Lure pages (trusted host)sites.google[.]com/corporateprofiledetails

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version