Cybersecurity professionals have long advised users to verify domain names before entering credentials. However, a newly observed phishing campaign is turning this fundamental advice on its head.
Threat actors are now tricking victims into authenticating directly on legitimate Microsoft portals, leveraging a technique known as Device Code Phishing.
Between April and May 2026, researchers uncovered a sophisticated campaign using password-protected PDF lures to hijack corporate accounts by exploiting the OAuth 2.0 Device Authorization Grant.
This protocol was originally designed to simplify logins for smart TVs, printers, and IoT devices lacking keyboards.
It allows a user to authorize an input-constrained device by entering a short code on a secondary device, like a smartphone, via an official Microsoft authentication page.
Attackers have weaponized this convenience to bypass traditional defenses and gain persistent access to victim environments.
PDF Lures Launch Phishing
The attack begins with a phishing email that often masquerades as a legal notice containing a password-protected PDF. Once the victim enters the provided password and opens the document, they are prompted to click a link to view further files.
Instead of pointing to a suspicious domain, the link often uses an open redirect on a legitimate Microsoft address or to other trusted platforms, such as the diagramming tool Cacoo, as seen in a recently observed targeted Brazilian variant.

After navigating through CAPTCHAs designed to evade automated security scanners, the victim arrives at a fake corporate portal. Here, they are instructed to copy a one-time user code.
This is the core of the exploit: the attacker’s server has already initiated a login request and generated this specific code.
When the victim clicks to copy the code, they are seamlessly redirected to the official Microsoft device login page.
Because the domain is genuinely Microsoft’s, the victim feels safe pasting the code and completing their standard Multi-Factor Authentication (MFA) process.
Once the victim approves the login, the Microsoft server issues an access token, an identity token, and a refresh token directly to the attacker’s application.

Armed with these tokens, the threat actor can silently read emails, exfiltrate sensitive files from OneDrive, and monitor Teams conversations without ever needing the victim’s actual password.
Because this attack relies on legitimate infrastructure and authorized token generation, traditional credential harvesting defenses often fall short.
Defending against Device Code Phishing requires a combination of strict corporate policies and heightened user awareness, securelist said.
End-users must also adapt their vigilance. It is no longer enough to verify the primary domain name. Users must be trained to inspect URLs for suspicious parameters, such as redirect markers, which attackers use to bounce traffic to malicious sites.
Most importantly, users should never approve an authorization request or enter a device code unless they personally initiated the login process on a nearby device.
By understanding the mechanics of Device Code Phishing and implementing proactive Conditional Access controls, organizations can close this dangerous loophole and secure their Microsoft environments against unauthorized access.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.