Csoonline GhostCode Phishing Kit Targets Microsoft 365 Accounts
Article Content
- •GhostCode exploits OAuth 2.0 for device code phishing targeting Microsoft 365.
- •Attackers use social engineering tactics, including impersonation and decoy documents.
- •Over 30 lookalike domains registered indicate a broader phishing campaign.
In late August 2026, eSentire's Threat Response Unit identified a phishing campaign dubbed 'GhostCode' that exploits Microsoft’s OAuth 2.0 device authorization flow to compromise Microsoft 365 accounts. Attackers impersonate procurement officers and lure victims into entering device codes on a phishing page that appears legitimate. Once victims authenticate, attackers gain access to authentication tokens, allowing them to register devices and maintain persistence within the victim’s Microsoft environment. The campaign has seen over 30 lookalike domains registered, indicating a broader targeting effort. The attackers employed social engineering tactics, including a decoy NDA document, to facilitate the attack. This method allows attackers to obtain long-lasting access tokens, including Primary Refresh Tokens (PRTs), which provide extensive access to the victim's Microsoft 365 environment. The attack's automation and evasion techniques, such as obfuscation and bot checks, enhance its effectiveness.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track BJ's Wholesale Club in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…