Cybercriminals are constantly evolving their techniques and are now turning to a particularly insidious attack method targeting Microsoft 365 accounts: OAuth device code phishing. This is a technique that exploits features Microsoft, making it extremely difficult to detect.

How OAuth device code phishing works
This method leverages the OAuth 2.0, which is designed for devices with limited input capabilities, such as smart TVs or IoT devices. In these cases, the user enters a short code on a central login page to authorize access.
Attackers exploit this very process, tricking users into entering passwords on genuine Microsoft pages. The result is full access to accounts 365, without technically breaching any security mechanisms.
See also: Wonderland: Android malware combines dropper, SMS theft and RAT capabilities
From email to full breach
The attack typically begins with a phishing email that appears as a document sharing notification, OneDrive message, or account security warning. The messages often come from compromised accounts or domains that appear trustworthy, reinforcing the illusion of legitimacy.
The user is prompted to click on a link, button, or even a QR code. From there, they are redirected to a phishing page that mimics Microsoft services and asks for email address . This action triggers the OAuth device authorization flow on the real Microsoft infrastructure.
A unique device code is then displayed , presented as a one-time code or verification token . The user is prompted to visit microsoft.com/devicelogin and enter the code. Since this is a genuine Microsoft page, suspicions are usually cleared.
The critical point: Legal access, illegal use
Once the process is complete and the user authenticates, the attacker's application receives an access token. This token allows full control of the Microsoft 365 account: access to email, files, Teams, and even the ability to move laterally within the corporate network.
The dangerous element is that the entire process relies on completely legitimate services, which makes detection through traditional security tools extremely difficult.
See also: Nigeria: RaccoonO365 developer arrested

The tools behind the campaigns
Proofpoint researchers have identified two key tools powering these attacks. SquarePhish2 , an advanced version of an older phishing framework, automates the OAuth process using QR codes and infrastructure controlled by the attackers. Its simple installation allows even less experienced criminals to launch mass attacks.
The second tool, Graphish, takes a different approach, creating fake login pages via Azure Application Registrations and reverse proxies. This facilitates ,man-in-the-middleattackscapturing credentials and session tokens even after successful MFA completion.
Economic and state incentives
The technique is not limited to one category of threat actors. Financially motivated groups, such as TA2723, began using OAuth device code phishing attacks in October 2025, sending emails purporting to contain payroll documents.
Meanwhile, state-backed actors have adopted the method. The UNK_AcademicFlare, with suspected links to Russia, has been conducting sophisticated social engineering campaigns using compromised government email addresses and deceptive URLs that mimic OneDrive, targeting government officials, academics, and researchers.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: WhatsApp accounts targeted by 'GhostPairing' attack

How can organisms defend themselves?
Defending against these types of attacks requires a change in approach. Organizations can implement Conditional Access policies that block device code authentication flows or restrict them to specific users and IP ranges. Requiring logins only from registered or compliant devices adds another layer of protection.
Equally critical is user education. The emphasis should not only be on suspicious links, but also on the risk of entering device codes from untrusted sources. The abuse of legitimate authentication mechanisms proves that phishing is evolving and requires more mature, tailored defense strategies.
