GhostCode Hijacks Microsoft 365 Accounts, Turning 14-Day OAuth Device Codes Into Persistent Access
Updated
Updated · Computerworld · Sep 18
GhostCode Hijacks Microsoft 365 Accounts, Turning 14-Day OAuth Device Codes Into Persistent Access
2 articles · Updated · Computerworld · Sep 18
Summary
eSentire said GhostCode is phishing Microsoft 365 users into entering legitimate OAuth device codes, letting attackers complete normal sign-in and MFA on an attacker-controlled device and steal authentication tokens.
Nine API calls in 78 seconds followed successful authentication in one observed case, with three devices registered at 28, 53 and 77 seconds; the third was enrolled into Intune, indicating an automated persistence workflow.
A stolen Primary Refresh Token can give SSO-like access across a victim’s M365 environment for 14 days by default, and eSentire said the attacker-created Intune device remained in the tenant even after token revocation.
The campaign used procurement-themed social engineering and an NDA HTML lure, while obfuscation, encrypted redirects, bot checks and Cloudflare Turnstile helped shield the phishing page from security tools.
eSentire urged defenders to restrict or disable device-code authentication where unnecessary, watch for multiple device registrations from one non-interactive session and python-requests activity after device-code logins.