Device-Code Phish + Fake Recruiter Interview Lures

About DFIR · High sophistication
Last updated September 24, 2026

This news roundup describes multiple real-world social engineering operations, including a device-code phishing service that stole access to over 12,000 inboxes and a North Korean campaign posing as recruiters to trick developers during fake coding interviews. The attackers used legitimate login pages, impersonation, and job-offer workflows to get victims to authenticate or run malicious code, then searched for invoices and wire-transfer conversations to monetize access.

Key findings

  • EvilTokens used device-code phishing to trick users into entering an authentication code on Microsoft’s real sign-in page, enabling access that could persist even after a password reset.
  • An AI chatbot was used to read stolen mailboxes and identify wire transfer conversations, vendor invoices, and the best people to impersonate.
  • The EvilTokens infrastructure was disrupted via a court order, with 50 websites seized and 150+ domains disabled; two suspects were arrested in London.
  • North Korea’s WaterPlum (Contagious Interview) posed as recruiters and ran fake coding interviews to get developers to execute malicious npm packages or open booby-trapped VS Code projects.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance/AP/AR, Executives and executive assistants, Software developers, Engineering management, Recruiting/HR.
  • Affected industries: Information technology / software development, Cryptocurrency / digital assets, Healthcare (via Health-ISAC membership exposure), Professional services (organizations broadly targeted via inbox compromise).
  • Attack channels: email, website, linkedin.
  • Impersonated: Microsoft sign-in / enterprise login flow, Recruiters for AI, crypto, and NFT companies.

Awareness takeaways

  • Treat unexpected authentication-code prompts as phishing, even if the login page looks legitimate.
  • If an email account is compromised, assume attackers will search for payment workflows; require out-of-band verification for invoices and wire transfers.
  • Train developers to treat “coding interview” tasks as a high-risk pathway, do not run unknown packages or projects without safeguards.

Red flags to watch for

  • Unexpected request to enter an authentication code you did not initiate
  • You are sent to complete a sign-in you didn’t start, even though the page is legitimate
  • Follow-on account activity can persist even after a password reset
  • Recruiter pushes you to run code or install packages as part of screening
  • Unverified project files sent for an interview task
  • Pressure to proceed without identity verification or standard hiring steps
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

EvilTokens used device-code phishing, which tricks victims into entering an authentication code on Microsoft’s real sign-in page. You get an email or website saying, 'Go to Microsoft, enter this code.' The page is 100% real, but the sign-in wasn’t started by you. Entering that code hands over access that can survive a password reset. At the same time, WaterPlum ran fake coding interviews on LinkedIn, posing as recruiters for AI, crypto, and NFT companies, pushing developers to run malicious npm packages and booby-trapped VS Code projects. Aha moment: if you didn’t start the login or the interview task, don’t trust it. Your move: stop, don’t enter the code or run the project, and report it to Security immediately.

Similar attacks

EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens was a phishing-as-a-service operation that used “device code phishing” to trick employees into authorizing an attacker session on Microsoft’s real login infrastructure, often bypassing MFA without stealing passwords. After access, attackers used AI to find payment-related conversations…

September 23, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
EvilTokens Takedown Exposes AI-Driven BEC Fraud

EvilTokens Takedown Exposes AI-Driven BEC Fraud

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service operation linked to more than 12,000 compromised Microsoft email inboxes across 10,000+ organizations. The service used AI to pick targets, impersonate trusted contacts, and steal session tokens so criminals could stay in…

September 22, 2026
EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026
Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft says it disrupted “EvilTokens,” an AI-assisted phishing service used to trick employees into authorizing attacker access via the device-code login flow (often used for TVs/printers). Victims who entered an attacker-provided code in their browser unknowingly granted access tokens that…

September 23, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026