Incident
Published 2026-09-15
Verified 2026-09-19

GhostCode: eSentire TRU documents M365 device-code phishing kit (MFA bypass in ~78s)

eSentire Threat Response Unit blog (published 15 September 2026; dateCreated 10 Sep) details GhostCode, a novel OAuth 2.0 device-authorization phishing kit that hijacks Microsoft 365 accounts after the victim completes legitimate MFA on Microsoft's real sign-in page. Observed chain: Salesforce contact-form lure as procurement staff, sales follow-up, NDA pretext, then a WeTransfer link to a password-gated HTML attachment with AES-256-GCM ciphertext and triple-layer HTML obfuscation; a Cloudflare Turnstile gate filters scanners before the device-code page. Kit requests a user_code using the Microsoft Authentication Broker application ID, presents a polished fake document portal, and captures tokens once the victim approves the attacker's device. eSentire describes Primary Refresh Token capture and, in one intrusion, nine successful API calls and three device registrations in about 78 seconds, with residential proxies matched to victim geography. Distinct from password-stealing kits; MFA does not stop the flow because the victim authenticates Microsoft directly. Defenders: restrict or block device-code grant where unused, alert on Authentication Broker device registrations, treat unexpected WeTransfer/NDA procurement mail as high-risk, review Entra ID sign-in and device logs. Primary: eSentire TRU; wire: Cyber Security News 16 Sep.

Product
Microsoft 365 / Entra ID — OAuth 2.0 device authorization grant (Authentication Broker client)
Versions
n/a (phishing kit abusing legitimate Microsoft device-code flow; not a Microsoft product CVE)
Exploited in Australia?
unknown
Patch to
Entra ID: disable device-code flow if unused; Conditional Access / risk alerts on Authentication Broker and new device registrations; user awareness on WeTransfer NDA lures; revoke tokens / remove rogue devices on suspicion

Primary: eSentire TRU — GhostCode device-code phishing kit (15 Sep 2026) · Vendor: eSentire — GhostCode analysis · Cyber Security News — GhostCode / M365 MFA bypass wire (16 Sep 2026)

tech identity cloud