GhostCode Phishing Kit Abuses Microsoft Device-Code Authentication to Steal Account Tokens

· Original article ↗

Summary

eSentire analyzed GhostCode, a device-code phishing kit that tricked a victim into authenticating through Microsoft’s legitimate sign-in page, enabling token theft, device enrollment, and email access.

Key points

  • The campaign used contact-form outreach impersonating a procurement officer, followed by an NDA lure delivered as a password-protected HTML file.
  • The HTML lure used junk padding, character-level comment injection, and password-derived AES-256-GCM encryption to conceal its redirect URL and evade analysis.
  • GhostCode abused Microsoft’s OAuth device authorization flow; after the victim completed sign-in and MFA, attackers obtained authentication tokens.
  • Within 78 seconds, attackers registered three devices, enrolled one in Intune, obtained a Primary Refresh Token, and accessed emails. MFA did not prevent this token-based access.
  • The campaign used rotating residential proxy IPs and bot-filtering checks. eSentire also found more than 30 similar lookalike domains registered in August 2026.
  • eSentire revoked the token grant, reset the victim’s credentials, disabled the attacker-enrolled devices, and developed detection coverage.
  • Recommended defenses include restricting device-code authentication, monitoring device registrations and suspicious python-requests activity, and hunting for rapid device enrollment.

Article Details

Attack Vectors
  • Threat actors posed as a procurement officer for BJ's Wholesale Club in a web sales contact form, then sent an NDA-themed follow-up email containing a WeTransfer link to a password-protected HTML file.
  • The HTML file used junk padding, character-level HTML comment injection, and a password-derived AES-256-GCM key to conceal its redirect URL until the victim entered the supplied password.
  • The redirect led through a JavaScript bot-filtering relay and a Cloudflare Turnstile gate to a device code phishing page.
  • The phishing page instructed the victim to enter an attacker-supplied code on Microsoft's legitimate device authorization page. After the victim completed sign-in and MFA, the attackers used the resulting tokens.
  • The attackers registered three devices, obtained a Primary Refresh Token, and harvested emails. They rotated proxy IP addresses during subsequent Microsoft requests.
Defensive Notes
  • Restrict or block device code authentication with Conditional Access except where explicitly required.
  • Consider MDM-based device compliance policies.
  • Alert on multiple device registrations from one non-interactive sign-in session and on device registrations associated with a python-requests user-agent.
  • Audit Entra enrolled devices for the reported firstname-lastname-companydomain-hexstring naming pattern and short bursts of registrations.
  • Hunt for successful deviceCode sign-ins followed within ten minutes by python-requests sign-ins for the same user, as described in the article's KQL query.
  • After compromise, revoke the token grant, reset affected credentials, and explicitly disable attacker-enrolled devices; the article notes that enrolled device records persist after token revocation.

Indicators of compromise

TypeIndicatorContext
DOMAINbjssourcing[.]comLookalike sender domain used to impersonate BJ's Wholesale Club during the reported outreach.
DOMAINgreenlightdlstribution[.]comSimilar lookalike domain identified by TRU as impersonating Green Light Distribution.
EMAILjeremyarcher@voewo[.]comDisposable email address used to register greenlightdlstribution[.]com and tied to other lookalike domains.
HOSTNAMEaccount-access-rc3uenqi[.]elitechiropracticandrehab[.]comSubdomain hosting the device code phishing server; TRU assessed the underlying site as likely compromised.
IPV4151[.]225[.]227[.]193Proxy exit IP observed during successful attacker token use.
IPV4176[.]253[.]248[.]175Proxy exit IP observed during successful attacker token use.
IPV45[.]230[.]71[.]51Frankfurt exit IP observed during the final successful attacker Intune enrollment.
IPV481[.]96[.]174[.]54Proxy exit IP observed during successful attacker token use.
IPV482[.]33[.]39[.]74Proxy exit IP observed during successful attacker token use.
IPV486[.]132[.]13[.]219Proxy exit IP observed during successful attacker token use.
IPV490[.]215[.]55[.]70Proxy exit IP observed during successful attacker token use.
IPV492[.]40[.]47[.]84Proxy exit IP observed during successful attacker token use.
IPV494[.]9[.]97[.]142Proxy exit IP observed during successful attacker token use.
URLhxxps[:]//chartered[.]flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d106d7Decrypted phishing redirect URL used as a relay, bot filter, and campaign-tracking endpoint.

MITRE ATT&CK

Threat Actors

Vendors

Products

Tools

Countries

Industries

Related Articles