Device-Code Phishing and “ClickFix” Lures Spread

The Hacker News · Medium sophistication
Last updated September 28, 2026

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session) and a newly weaponized placeholder domain that serves a “ClickFix” lure to Windows users.

Key findings

  • A non-reserved placeholder domain (third-party[.]com) was registered by an attacker and used to deliver a Windows-focused “ClickFix lure,” impacting readers of documentation and code that hard-coded the domain.
  • A Microsoft-led action dismantled the “EvilTokens” phishing service, which specialized in “device code” phishing, tricking victims into authorizing an attacker’s session without sharing passwords.
  • A TeamFiltration campaign targeted Microsoft 365 tenants and successfully compromised unmanaged service/functional accounts, highlighting risk from “forgotten” non-human identities without MFA.
  • Konni used spear-phishing with ZIP files containing malicious LNK shortcuts disguised as PDFs to deliver malware to Ukraine-focused targets.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, IT/Helpdesk, Developers/Engineering, Identity & Access Management (IAM) team.
  • Affected industries: Retail, Finance, Government/Public sector, Technology/SaaS (Microsoft 365 tenants).
  • Attack channels: email, website.
  • Impersonated: IT support or a cloud app sign-in prompt (device activation), Legitimate documentation/reference link (developer docs or internal wiki), A document sender sharing a PDF (actually a shortcut file).

Awareness takeaways

  • Treat ‘device code’ requests as high-risk, only enter codes on official sites you navigated to yourself (not from links).
  • Don’t trust “placeholder” domains in docs unless they are reserved examples (like example.com) or explicitly approved by your organization.
  • Be suspicious of ZIP attachments and ‘PDFs’ that are actually shortcuts (LNK). If a document arrives compressed, verify with the sender via a known channel.
  • Harden and monitor service/functional accounts (MFA, password rotation, ownership) because attackers target ‘forgotten’ non-human identities.

Red flags to watch for

  • Any request to enter a ‘short code’ into a link/page you didn’t initiate
  • Message claims you must ‘complete authentication’ but you never started a login
  • Unusual urgency to approve access for a ‘device’ you don’t recognize
  • Links that look like documentation placeholders but are real, registered domains
  • Site shows different content depending on device/OS (decoy vs lure)
  • Unexpected ‘fix your system’ prompts when you expected documentation
  • ‘PDF’ file that is actually a shortcut (.LNK), especially inside a ZIP
  • Unexpected compressed attachment for a simple document
  • File icon/name looks like a PDF but file type/extension is suspicious
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Enter this short code to complete authentication for your device.” But… you never tried to sign in. This is device-code phishing, like the EvilTokens service. You type that code into their page, and boom, you’ve just approved their session into your Microsoft 365 without ever giving them your password. Same idea with the ClickFix lure: docs hard-coded to third-party.com now lead to a fake Windows “Click to fix” page instead of harmless examples. One click, and you’re running their code, not reading documentation. Aha rule: if you didn’t start the login or expect the link, never enter a device code or click a “fix” button. Instead, go to the official site or app yourself and check from there.

Similar attacks

Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Device-Code Phish + Fake Recruiter Interview Lures

Device-Code Phish + Fake Recruiter Interview Lures

This news roundup describes multiple real-world social engineering operations, including a device-code phishing service that stole access to over 12,000 inboxes and a North Korean campaign posing as recruiters to trick developers during fake coding interviews. The attackers used legitimate login…

September 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
EvilTokens Uses Device Codes to Bypass MFA

EvilTokens Uses Device Codes to Bypass MFA

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly…

September 22, 2026