
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
This article demonstrates a phishing method that tricks users into signing in on Microsoft’s real login page and approving access for an attacker-controlled app. Instead of stealing a password, the attacker captures a valid Microsoft access token that can be used to access Microsoft 365 data like email, OneDrive, SharePoint, and Teams.
The attack begins with an email that claims Microsoft detected unusual sign-in activity and urges the recipient to secure their account immediately. Instead of linking directly to a fake Microsoft login page, the email sends the victim to an attacker-controlled verification site first. That site displays a device code and instructions, along with a button that opens Microsoft's genuine Device Login page at login.microsoftonline.com.
The victim enters the code on Microsoft's real domain and clicks Continue, believing they are verifying or protecting their account. In reality, they are approving an authorization request for an attacker-controlled application. Once approved, the attacker receives a valid Microsoft access token rather than a password, which can be used through Microsoft Graph to reach resources such as email, OneDrive, SharePoint, and Teams, depending on the permissions granted.
This technique is effective because it abuses a legitimate Microsoft authentication workflow rather than imitating it. Every critical step, including the sign-in itself, happens on Microsoft's real domain, which removes the usual visual cues people are trained to spot, like misspelled URLs or fake login pages. The attacker-controlled site only handles the initial redirect and code display, while Microsoft's own infrastructure handles the sensitive part of the flow, making it harder for victims to sense anything is wrong.
Organizations and individuals can reduce risk from this technique by treating any unrequested device-code or authentication prompt as suspicious and verifying it through a separate, trusted channel before proceeding. Employees should be reminded that seeing Microsoft's legitimate domain during a login flow is not proof the overall request is safe, since attackers can trigger real login steps as part of a larger scheme. Regularly reviewing and removing unfamiliar applications connected to a Microsoft account, and revoking sessions and permissions quickly if an unexpected approval occurs, can limit the damage if someone does approve a request by mistake. Security and IT teams should also reinforce awareness of urgency-based lures, such as claims of unusual sign-in activity, since this pressure tactic is central to getting victims to act without pausing to verify.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a phishing technique where a victim is led to enter a code on Microsoft's legitimate device login page, unknowingly authorizing an attacker-controlled application to access their account.
No, the attacker captures a valid Microsoft access token rather than a password, which can then be used to access Microsoft 365 resources like email, OneDrive, and Teams.
Because every key step, including the actual sign-in, happens on Microsoft's real login domain, which makes the flow look trustworthy even though the victim is authorizing an attacker's app.
Red flags include receiving an unexpected urgent email about unusual sign-in activity, being sent to a separate verification site before reaching Microsoft, and being asked to approve access to an app the user did not intend to connect.
You get an email: “Microsoft detected unusual sign-in activity. Secure your account now.” Looks urgent, looks legit, right? You click. It sends you to a fake ‘Microsoft verification portal’ with a device code and a big button. That button opens the real Microsoft Device Login page at login.microsoftonline.com. You sign in, see Microsoft’s real domain, and click Continue, thinking you’re protecting your account. Aha: you just approved an attacker-controlled app that grabs a Microsoft access token to your email, OneDrive, SharePoint, maybe even Teams. Remember this: if you didn’t start a sign-in or device-code flow yourself, don’t approve it. Close it, then check your Microsoft account security from the official portal instead.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…