Device Code-based OAuth Phishing

Mar 23, 2026 ยท 1 min read

This active campaign abuses Microsoft’s legitimate device-code OAuth flow to capture application tokens instead of passwords. Victims interact with a real Microsoft sign-in page while the attacker’s infrastructure obtains the resulting token in the background.

The phishing pages combine trusted authentication flows with obfuscated payloads, developer-tool detection and debugger traps. A captured OAuth token can provide application-level access to email, files and identity data without exposing the victim’s password.

Read the full Unit 42 report and indicators โ†’