SECURITY researchers have uncovered a phishing kit known as GhostCode that abuses Microsoft’s OAuth 2.0 device authorisation flow to target enterprise sales teams and service providers across North America. According to eSentire’s Threat Response Unit (TRU), an unidentified, financially motivated cybercrime cluster contacts organisations through legitimate web forms while posing as procurement executives.
After building trust, the attackers send a password-protected HTML attachment disguised as a file-transfer link. It opens a fake FlipBook document portal and ultimately directs victims to a fraudulent sign-in page.
GhostCode displays a device code and sends the victim to Microsoft’s genuine device-login page, where they enter the code and complete multi-factor authentication. The attackers then capture the resulting session tokens and present a fake non-disclosure agreement to conceal the compromise. The attachment uses thousands of junk characters, comments inserted between visible characters and AES-256-GCM encryption to hinder scanning and analysis.
TRU said that, in one incident, attackers registered three rogue devices within 78 seconds and obtained a Primary Refresh Token 32 seconds after login, potentially enabling access across a Microsoft 365 tenant. More than 30 lookalike domains were registered in August 2026 to imitate distributors, food suppliers and warehousing companies.
The report recommends restricting OAuth device-code authentication, particularly for standard desktop users, and applying conditional-access policies requiring compliant, corporate-managed devices. Security teams should also monitor directory logs for rapid device registrations and suspicious device naming patterns, while customer-facing staff should verify unexpected business approaches and external file links.