Cloud Security Alliance
OAuth Device Code Phishing Attack Analysis
Pages
12
Time to read
16 mins
Publication
Language
English
Pages
12
Time to read
16 mins
Publication
Language
English
This technical report details the mechanics and implications of OAuth device code phishing, a method that exploits a legitimate protocol feature to harvest Microsoft 365 access tokens without requiring user credentials on a fraudulent site. The report outlines how this attack, which began as a state-sponsored technique, has evolved into a commoditized service known as Phishing-as-a-Service (PhaaS), exemplified by the EvilTokens platform that compromised over 340 organizations across multiple countries. It explains the attack's initiation through legitimate Microsoft endpoints, the role of multifactor authentication, and the persistence of refresh tokens post-compromise. The report also discusses detection opportunities using Microsoft Entra ID sign-in logs and provides recommendations for organizations to mitigate risks associated with device code flow. Security teams are advised to audit legitimate uses of device code flow and implement monitoring and revocation procedures to counteract potential threats effectively.