OAuth Abuse: The Rise of Device Code Phishing Campaigns episode artwork

EPISODE · Mar 29, 2026 · 23 MIN

OAuth Abuse: The Rise of Device Code Phishing Campaigns

from Decoded: The Cybersecurity Podcast · host Edward Henriquez

Cybersecurity researchers have identified a widespread phishing campaign targeting hundreds of Microsoft 365 organizations across five countries by exploiting OAuth device authorization flows. This sophisticated attack tricks users into entering legitimate device codes on authentic Microsoft login pages, allowing hackers to bypass multi-factor authentication and maintain access even after password resets. The operation utilizes a diverse range of lures, such as fake DocuSign notifications and construction bids, while leveraging Cloudflare Workers and Railway infrastructure to host malicious redirect chains. These attacks are linked to a new phishing-as-a-service platform called EvilTokens, which provides automated tools for credential harvesting and spam filter evasion. To remain undetected, the landing pages employ anti-analysis techniques that disable developer tools and block browser-based inspections. Experts recommend that organizations monitor sign-in logs for specific IP addresses and revoke OAuth refresh tokens to mitigate the threat.

Episode metadata supplied by the publisher feed · Published Mar 29, 2026

Embed this episode

NOW PLAYING

OAuth Abuse: The Rise of Device Code Phishing Campaigns

0:00 23:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Decoded: The Cybersecurity Podcast?

This episode is 23 minutes long.

When was this Decoded: The Cybersecurity Podcast episode published?

This episode was published on March 29, 2026.

Can I download this Decoded: The Cybersecurity Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!