Tool
GhostCode
- First Reported
- Sep 15, 2026
- Latest Reported
- Sep 15, 2026
Reported Context (1)
- officer of a legitimate business. TRU is tracking the device code phishing kit used in the campaign as "GhostCode". The name reflects two characteristics observed during analysis: "Ghost" refers to GHOSTnet ASN GhostCode Phishing Kit Abuses Microsoft Device-Code Authentication to Steal Account Tokens
Threat Actors (1)
MITRE ATT&CK (9)
Vendors (3)
Products (8)
Tools (1)
Industries (2)
Countries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.