GhostCode Phishing Kit Abuses Microsoft Device-Code Authentication to Steal Account Tokens

Summary
eSentire analyzed GhostCode, a device-code phishing kit that tricked a victim into authenticating through Microsoft’s legitimate sign-in page, enabling token theft, device enrollment, and email access.
Key points
- The campaign used contact-form outreach impersonating a procurement officer, followed by an NDA lure delivered as a password-protected HTML file.
- The HTML lure used junk padding, character-level comment injection, and password-derived AES-256-GCM encryption to conceal its redirect URL and evade analysis.
- GhostCode abused Microsoft’s OAuth device authorization flow; after the victim completed sign-in and MFA, attackers obtained authentication tokens.
- Within 78 seconds, attackers registered three devices, enrolled one in Intune, obtained a Primary Refresh Token, and accessed emails. MFA did not prevent this token-based access.
- The campaign used rotating residential proxy IPs and bot-filtering checks. eSentire also found more than 30 similar lookalike domains registered in August 2026.
- eSentire revoked the token grant, reset the victim’s credentials, disabled the attacker-enrolled devices, and developed detection coverage.
- Recommended defenses include restricting device-code authentication, monitoring device registrations and suspicious python-requests activity, and hunting for rapid device enrollment.
Article Details
- Attack Vectors
- Threat actors posed as a procurement officer for BJ's Wholesale Club in a web sales contact form, then sent an NDA-themed follow-up email containing a WeTransfer link to a password-protected HTML file.
- The HTML file used junk padding, character-level HTML comment injection, and a password-derived AES-256-GCM key to conceal its redirect URL until the victim entered the supplied password.
- The redirect led through a JavaScript bot-filtering relay and a Cloudflare Turnstile gate to a device code phishing page.
- The phishing page instructed the victim to enter an attacker-supplied code on Microsoft's legitimate device authorization page. After the victim completed sign-in and MFA, the attackers used the resulting tokens.
- The attackers registered three devices, obtained a Primary Refresh Token, and harvested emails. They rotated proxy IP addresses during subsequent Microsoft requests.
- Defensive Notes
- Restrict or block device code authentication with Conditional Access except where explicitly required.
- Consider MDM-based device compliance policies.
- Alert on multiple device registrations from one non-interactive sign-in session and on device registrations associated with a python-requests user-agent.
- Audit Entra enrolled devices for the reported firstname-lastname-companydomain-hexstring naming pattern and short bursts of registrations.
- Hunt for successful deviceCode sign-ins followed within ten minutes by python-requests sign-ins for the same user, as described in the article's KQL query.
- After compromise, revoke the token grant, reset affected credentials, and explicitly disable attacker-enrolled devices; the article notes that enrolled device records persist after token revocation.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | bjssourcing[.]com | Lookalike sender domain used to impersonate BJ's Wholesale Club during the reported outreach. |
| DOMAIN | greenlightdlstribution[.]com | Similar lookalike domain identified by TRU as impersonating Green Light Distribution. |
jeremyarcher@voewo[.]com | Disposable email address used to register greenlightdlstribution[.]com and tied to other lookalike domains. | |
| HOSTNAME | account-access-rc3uenqi[.]elitechiropracticandrehab[.]com | Subdomain hosting the device code phishing server; TRU assessed the underlying site as likely compromised. |
| IPV4 | 151[.]225[.]227[.]193 | Proxy exit IP observed during successful attacker token use. |
| IPV4 | 176[.]253[.]248[.]175 | Proxy exit IP observed during successful attacker token use. |
| IPV4 | 5[.]230[.]71[.]51 | Frankfurt exit IP observed during the final successful attacker Intune enrollment. |
| IPV4 | 81[.]96[.]174[.]54 | Proxy exit IP observed during successful attacker token use. |
| IPV4 | 82[.]33[.]39[.]74 | Proxy exit IP observed during successful attacker token use. |
| IPV4 | 86[.]132[.]13[.]219 | Proxy exit IP observed during successful attacker token use. |
| IPV4 | 90[.]215[.]55[.]70 | Proxy exit IP observed during successful attacker token use. |
| IPV4 | 92[.]40[.]47[.]84 | Proxy exit IP observed during successful attacker token use. |
| IPV4 | 94[.]9[.]97[.]142 | Proxy exit IP observed during successful attacker token use. |
| URL | hxxps[:]//chartered[.]flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d106d7 | Decrypted phishing redirect URL used as a relay, bot filter, and campaign-tracking endpoint. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe HTML lure combined junk padding, comments between visible characters, and an encrypted redirect URL to conceal its phishing content.T1090.002 · External ProxyThe attackers rotated residential proxy exit IPs during Microsoft API requests, with traffic largely matching the victim's country.T1098.005 · Device RegistrationThe attackers registered three devices through the Device Registration Service using the stolen device code token, creating additional access paths.T1204.002 · Malicious FileThe victim opened the password-protected HTML file, which decrypted a redirect to the phishing infrastructure.T1497.001 · System ChecksThe relay used a JavaScript browser challenge, while the phishing kit filtered requests by IP address and user-agent to block automated analysis.T1528 · Steal Application Access TokenGhostCode induced the victim to complete Microsoft device code authorization so its backend could obtain authentication tokens.T1550.001 · Application Access TokenThe attackers used the stolen token for successful Microsoft API calls immediately after device code authentication.T1566.002 · Spearphishing LinkThe NDA-themed follow-up email sent the victim a WeTransfer link to the password-protected HTML lure.T1583.001 · DomainsThe actors registered a lookalike domain before outreach; TRU also identified similar recently registered impersonation domains.
Threat Actors
Vendors
Cloudflarephishing server at "account-access-rc3uenqi.elitechiropracticandrehab[.]com" and is presented with a Cloudflare Turnstile challenge. The root domain appears to belong to a legitimate chiropractic clinic, suggestingFlashProxy[.]io/api/harvester?action=geoip to look up the victim's external location and activate a proxy through FlashProxy[.]io, a residential/rotating proxy provider. This allows attacker traffic to appear geographically alignedMicrosoftenrollment and the hidden, obfuscated code within the HTML lure; "Code" refers to the kit's abuse of Microsoft device code authorization.
Products
Azure ADAzure AD device registration - 3 devicesCloudflare Turnstileserver at "account-access-rc3uenqi.elitechiropracticandrehab[.]com" and is presented with a Cloudflare Turnstile challenge. The root domain appears to belong to a legitimate chiropractic clinic, suggesting theEntraThe following device names were identified in Entra audit logs for each of the three devices. Note, a1123aab is the first eight characters of the victim's tenant ID and the -p01/-p02 suffix are an incrementing retryIntuneMicrosoft Intune EnrollmentMicrosoft Authentication Broker Apprequest, and notably, uses the specific App ID, 29d9ed98-a469-4536-ade2-f981bc1d605e (Microsoft Authentication Broker App) in this request:Microsoft GraphMicrosoft GraphSalesforceThreat actors initiated the attack by submitting a seemingly innocuous inquiry through Salesforce. After the sales team followed up, the threat actors replied that a subsequent email would be sent to "sign an NDA". TheWeTransferactors replied that a subsequent email would be sent to "sign an NDA". The follow-up email contained a WeTransfer link to a password-gated HTML attachment.
Tools
EvilTokensvia AES-256-GCM with the threat actor supplied password. This technique has also been observed in the EvilTokens phishing kit. In this case, however, the AES key is not generated server-side. Instead, it is derivedGhostCodeofficer of a legitimate business. TRU is tracking the device code phishing kit used in the campaign as "GhostCode". The name reflects two characteristics observed during analysis: "Ghost" refers to GHOSTnet ASN
Countries
Germanyof the nine came from UK residential ISPs; the final Intune enrollment of 5e83a216 came from Frankfurt, Germany (ASN 12586, GHOSTnet GmbH):United Kingdomto the victim read "You're signing into Microsoft Authentication Broker on another device located in United Kingdom." By routing the device code request through a UK IP, the attacker ensured this geolocation matchedUnited States