Device Code-based OAuth Phishing
Mar 23, 2026
ยท
1 min read
This active campaign abuses Microsoft’s legitimate device-code OAuth flow to capture application tokens instead of passwords. Victims interact with a real Microsoft sign-in page while the attacker’s infrastructure obtains the resulting token in the background.
The phishing pages combine trusted authentication flows with obfuscated payloads, developer-tool detection and debugger traps. A captured OAuth token can provide application-level access to email, files and identity data without exposing the victim’s password.