OAuth Abuse: The Rise of Device Code Phishing Campaigns episode artwork

EPISODE · Mar 29, 2026 · 23 MIN

OAuth Abuse: The Rise of Device Code Phishing Campaigns

from Decoded: The Cybersecurity Podcast · host Edward Henriquez

Cybersecurity researchers have identified a widespread phishing campaign targeting hundreds of Microsoft 365 organizations across five countries by exploiting OAuth device authorization flows. This sophisticated attack tricks users into entering legitimate device codes on authentic Microsoft login pages, allowing hackers to bypass multi-factor authentication and maintain access even after password resets. The operation utilizes a diverse range of lures, such as fake DocuSign notifications and construction bids, while leveraging Cloudflare Workers and Railway infrastructure to host malicious redirect chains. These attacks are linked to a new phishing-as-a-service platform called EvilTokens, which provides automated tools for credential harvesting and spam filter evasion. To remain undetected, the landing pages employ anti-analysis techniques that disable developer tools and block browser-based inspections. Experts recommend that organizations monitor sign-in logs for specific IP addresses and revoke OAuth refresh tokens to mitigate the threat.

NOW PLAYING

OAuth Abuse: The Rise of Device Code Phishing Campaigns

0:00 23:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of Decoded: The Cybersecurity Podcast?

This episode is 23 minutes long.

When was this Decoded: The Cybersecurity Podcast episode published?

This episode was published on March 29, 2026.

What is this episode about?

Cybersecurity researchers have identified a widespread phishing campaign targeting hundreds of Microsoft 365 organizations across five countries by exploiting OAuth device authorization flows. This sophisticated attack tricks users into entering...

Can I download this Decoded: The Cybersecurity Podcast episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!