SquarePhish - Tool

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 18, 2025
Last Seen
January 7, 2026

SquarePhish is a phishing-based attack tool that exploits the OAuth2 device code authorization flow to gain access to victim accounts and enable account takeover.

Overview

SquarePhish is a phishing-based attack tool that exploits the OAuth2 device code authorization flow to gain access to victim accounts and enable account takeover. It persuades targets to authorize an attacker-controlled application via a device-code prompt, leveraging legitimate device code mechanisms rather than traditional credential theft. This represents a notable evolution in phishing tactics, expanding abuse of device-code flows in pursuit of account compromise.

Related Threat Clusters

Recent Intelligence Reports

  • Proofpoint warns of surge in Microsoft device code phishing — Itbrief · January 7, 2026
  • Access granted: phishing with device code authorization for account takeover — Proofpoint · December 18, 2025

CVSS v3.1 Breakdown