GhostCode Phishing Kit Exploits OAuth Flaw to Hijack Microsoft 365 Accounts
A phishing kit called GhostCode is targeting Microsoft 365 users by exploiting a weakness in the OAuth 2.0 device authorization flow.
The attackers pose as devices that need to be authenticated, such as IoT devices or smart TVs, and obtain a device code from Microsoft's OAuth.
The victim is then tricked into entering this code on Microsoft's authentication page, allowing the attacker-controlled device to obtain authentication tokens.
These tokens are used to register additional devices, obtain credentials, and establish persistence in the victim's Microsoft environment.