Hackers target Microsoft Entra accounts in device code vishing attacks
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。首先,我得仔细阅读文章,理解主要信息。 文章讲的是网络攻击者利用设备代码钓鱼和语音钓鱼(vishing)结合攻击技术、制造业和金融组织。他们滥用OAuth 2.0的设备授权流程,获取有效的认证令牌,进而访问受害者账户,而不需要传统的钓鱼网站。攻击者使用合法的Microsoft OAuth客户端ID,让受害者输入用户代码到微软的设备登录页面,从而绕过多因素认证。 然后,攻击者可以获取刷新令牌和访问令牌,进而访问各种SaaS应用。文章还提到ShinyHunters团伙可能参与其中,并建议管理员采取措施防御。 现在我需要把这些信息浓缩到100字以内。要突出攻击方式、目标行业、滥用的机制以及带来的影响。同时保持语言简洁明了。 可能的结构:攻击者结合设备代码钓鱼和语音钓鱼攻击技术、制造业和金融行业,滥用OAuth 2.0设备授权流程获取令牌,绕过多因素认证,访问账户和应用。 检查一下字数是否在限制内,并确保没有遗漏关键点。 </think> 网络攻击者结合设备代码钓鱼和语音钓鱼(vishing)攻击技术,针对技术、制造和金融行业组织展开行动。他们滥用OAuth 2.0设备授权流程获取有效认证令牌,绕过多因素认证并访问受害者账户及单点登录应用。 2026-2-19 12:45:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:6 收藏

Microsoft

Threat actors are targeting technology, manufacturing, and financial organizations in campaigns that combine device code phishing and voice phishing (vishing) to abuse the OAuth 2.0 Device Authorization flow and compromise Microsoft Entra accounts.

Unlike previous attacks that utilized malicious OAuth applications to compromise accounts, these campaigns instead leverage legitimate Microsoft OAuth client IDs and the device authorization flow to trick victims into authenticating.

This provides attackers with valid authentication tokens that can be used to access the victim's account without relying on regular phishing sites that steal passwords or intercept multi-factor authentication codes.

Wiz

A source told BleepingComputer they believed the ShinyHunters extortion gang was behind the new device code vishing attacks, which the threat actors later confirmed. BleepingComputer has not been able to confirm this independently.

ShinyHunters was recently linked to vishing attacks used to  breack Okta and Microsoft Entra SSO accounts for data theft attacks.

BleepingComputer contacted Microsoft about these attacks but was told it had nothing to share at this time.

Device code social engineering attacks

BleepingComputer has learned from multiple sources that threat actors have begun using vishing social engineering attacks that no longer require attacker-controlled infrastructure, instead leveraging legitimate Microsoft login forms and standard device code authentication workflows to breach corporate accounts.

A device code phishing attack is when the legitimate OAuth 2.0 device authorization grant flow is abused to obtain authentication tokens for the victim's Microsoft Entra account.

This can then be used to gain access to the user's resources and connected SSO applications, like Microsoft 365, Salesforce, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, Atlassian, and many others.

This grant flow was designed to make it easy to connect devices that lack accessible input options, such as IoT devices, printers, streaming devices, and TVs.

"The Microsoft identity platform supports the device authorization grant, which allows users to sign in to input-constrained devices such as a smart TV, IoT device, or a printer," explains Microsoft.

"To enable this flow, the device has the user visit a webpage in a browser on another device to sign in. Once the user signs in, the device is able to get access tokens and refresh tokens as needed."

This authentication flow is similar to what you see when logging into a streaming service, such as Netflix or Apple TV, where the streaming device displays a short code and instructs you to visit a website on your phone or computer to complete sign-in.

After you enter the code and authenticate, the device is automatically linked to your account without ever handling your password directly.

To conduct a device-code phishing attack, threat actors need the client_id of an existing OAuth app, which can be their own or one of Microsoft's existing apps.

Using open-source tools, the attackers generate a "device_code" and "user_code" that will be shared with the target for the specified OAuth app. 

The threat actors then contact a targeted employee and attempt to convince them to enter the generated user_code on the Microsoft device authentication page, microsoft.com/devicelogin

Microsoft's device authentication form
Microsoft's device authentication form

When the targeted person enters the code, they will be prompted to log in with their credentials and complete any MFA verifications, just as they normally would when logging in. After authenticating, Microsoft displays the name of the OAuth application that was authorized.

However, because threat actors can use legitimate apps, even those from Microsoft, this can lend more legitimacy and trust to the authentication process.

Microsoft Authentication Broker OAuth app now connected to an account
Microsoft Authentication Broker OAuth app now connected to an account

Once the OAuth app is connected to an account, threat actors can use the device_code to retrieve the targeted employee's refresh token, which can then be exchanged for access tokens.

Those access tokens allow attackers to access the employee's Microsoft services without having to complete multi-factor authentication again, since MFA was already completed during the initial login.

The threat actors can now authenticate as the user in Microsoft Entra and access SaaS applications configured with SSO (single sign-on) in the victim's tenant, enabling the theft of corporate data for extortion.

KnowBe4 Threat Labs also discovered a recent campaign that uses traditional phishing emails and websites to deliver device code attacks.

The company first spotted the campaign in December 2025 and said it relies heavily on social engineering lures such as fake payment configuration prompts, document-sharing alerts, and bogus voicemail notifications.

Malicious pages used in the campaign
Malicious pages used in the campaign
Source: KnowBe4

KnowBe4 recommends that Microsoft 365 account holders block the malicious domains and sender addresses, audit and revoke suspicious OAuth app consents, and review Azure AD sign-in logs for device code authentication events.

Administrators are also recommended to turn off the device code flow option when not required and to enforce conditional access policies.

Device code phishing is not new, with multiple threat actors having used this method to breach accounts in the past.

In February 2025, the Microsoft Threat Intelligence Center warned that Russian hackers were targeting Microsoft 365 accounts using device code phishing.

In December, ProofPoint reported similar attacks that use a similar phishing kit seen by KnowBe4 to breach Microsoft accounts.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/
如有侵权请联系:admin#unsafe.sh