SquarePhish is a phishing-based attack tool that exploits the OAuth2 device code authorization flow to gain access to victim accounts and enable account takeover.
Overview
SquarePhish is a phishing-based attack tool that exploits the OAuth2 device code authorization flow to gain access to victim accounts and enable account takeover. It persuades targets to authorize an attacker-controlled application via a device-code prompt, leveraging legitimate device code mechanisms rather than traditional credential theft. This represents a notable evolution in phishing tactics, expanding abuse of device-code flows in pursuit of account compromise.
Related Threat Clusters
-
Surge in Microsoft 365 Account Takeovers via OAuth Device Code Phishing
Proofpoint has reported a significant rise in account takeovers of Microsoft 365 users due to the exploitation of Microsoft's OAuth device code authorization flow. Attackers are using a legitimate login process to trick…
2 articles · Updated January 7, 2026 -
Surge in OAuth Device Code Phishing Targeting Microsoft 365 Accounts
A rise in phishing campaigns exploiting Microsoft's OAuth device code authorization has been reported, affecting Microsoft 365 accounts. Threat actors, including state-aligned and financially motivated groups, are using…
6 articles · Updated December 18, 2025
Recent Intelligence Reports
- Proofpoint warns of surge in Microsoft device code phishing — Itbrief · January 7, 2026
- Access granted: phishing with device code authorization for account takeover — Proofpoint · December 18, 2025