GhostCode Tricks Users Into Device-Code Login

CSO Online · High sophistication
Last updated September 18, 2026

Researchers observed a real phishing campaign using a kit called GhostCode that abuses Microsoft’s legitimate “device code” sign-in flow to steal authentication tokens. Victims are socially engineered to open an NDA-themed HTML file and then enter a device code on Microsoft’s login page, unintentionally authorizing an attacker-controlled device. The stolen tokens are then used to register devices and maintain persistent access to the victim’s Microsoft 365 environment.

Key findings

  • GhostCode abuses Microsoft’s OAuth 2.0 device authorization grant flow (device-code phishing) to obtain authentication tokens tied to an attacker-controlled device.
  • The observed campaign used a multi-step social-engineering workflow: initial outreach via a web contact form posing as procurement, then an NDA-themed HTML lure that leads to a device-code phishing page.
  • After successful authentication, attackers automated rapid post-login actions (API calls) to register multiple devices and enroll one into Intune for persistence.
  • Intune enrollment may survive token revocation; the attacker-created device can remain until explicitly removed.
  • Attackers used evasion tactics such as obfuscated HTML, encrypted redirects, bot checks, and Cloudflare Turnstile to hinder security tooling.

Who’s being targeted

  • Commonly targeted roles: All employees (Microsoft 365 users), Procurement, Sales, Legal, IT Helpdesk, Identity & Access Management (Entra ID/Azure AD) admins, Security Operations.
  • Affected industries: Any organization using Microsoft 365.
  • Attack channels: website, email.
  • Impersonated: Procurement officer.

Awareness takeaways

  • Treat requests to enter a "device code" as high risk unless you personally initiated a device sign-in; verify with IT/security before proceeding.
  • Be suspicious of NDAs (or other documents) sent as HTML files, do not open them; request a PDF via known business channels.
  • Identity/security teams should watch for rapid device registrations and automation patterns immediately after device-code authentication.
  • If an attacker enrolls a device into Intune, removing tokens may not be enough, explicitly review and remove unknown devices from Entra ID/Intune.

Red flags to watch for

  • Unexpected NDA delivered as an HTML file
  • Being instructed to enter a device code to access a document
  • A login/MFA flow that is described as authorizing a "device" rather than you accessing a normal business app
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a legit-looking procurement inquiry on your website, then an NDA to review. Normal day, right? But this is GhostCode. That HTML NDA quietly sends you to a Microsoft page asking you to enter a device code to view the document. You sign in and pass MFA like normal, but here’s the twist: you just approved an attacker-controlled device. They grab your tokens, register devices, even enroll one into Intune that can survive token revocation. Aha moment: NDAs do not need a device code. If you’re ever told to enter a Microsoft device code just to open a document, stop and call IT before you touch it.

Similar attacks

Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
M365 Direct Send Spoofs Internal HR & Finance

M365 Direct Send Spoofs Internal HR & Finance

Researchers observed a real phishing campaign that abused Microsoft 365’s “Direct Send” feature to deliver messages that looked like they came from trusted internal addresses (HR, accounting, admin). The emails commonly used familiar business lures like invoices, payment approvals, voicemail…

September 11, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026