Skip to content
GhostCode Phishing Kit Targets Microsoft 365 Accounts

GhostCode Phishing Kit Targets Microsoft 365 Accounts

First seen 18 Sep 2026, 16:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 18:54 UTC
  • GhostCode exploits OAuth 2.0 for device code phishing targeting Microsoft 365.
  • Attackers use social engineering tactics, including impersonation and decoy documents.
  • Over 30 lookalike domains registered indicate a broader phishing campaign.

In late August 2026, eSentire's Threat Response Unit identified a phishing campaign dubbed 'GhostCode' that exploits Microsoft’s OAuth 2.0 device authorization flow to compromise Microsoft 365 accounts. Attackers impersonate procurement officers and lure victims into entering device codes on a phishing page that appears legitimate. Once victims authenticate, attackers gain access to authentication tokens, allowing them to register devices and maintain persistence within the victim’s Microsoft environment. The campaign has seen over 30 lookalike domains registered, indicating a broader targeting effort. The attackers employed social engineering tactics, including a decoy NDA document, to facilitate the attack. This method allows attackers to obtain long-lasting access tokens, including Primary Refresh Tokens (PRTs), which provide extensive access to the victim's Microsoft 365 environment. The attack's automation and evasion techniques, such as obfuscation and bot checks, enhance its effectiveness.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-15
GhostCode campaign identified
eSentire's Threat Response Unit detected the GhostCode phishing campaign targeting Microsoft 365 users.
eSentire
2026-08-15
Lookalike domains registered
Over 30 domains impersonating US-based companies were registered, indicating a broader campaign.
eSentire
2026-09-18
Public disclosure of GhostCode
Multiple outlets reported on the GhostCode phishing kit and its implications for Microsoft 365 users.
CSO Online
2026-09-18
Attack method detailed
Reports detailed how GhostCode allows attackers to obtain authentication tokens and maintain access.
Computerworld

More articles in this cluster (3)

Following this threat?

Track BJ's Wholesale Club in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed