{"id":1983,"date":"2025-02-14T10:03:40","date_gmt":"2025-02-14T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/14\/new-device-code-phishing-attack-exploit-device-code-authentication-to-capture-authentication-tokens\/"},"modified":"2025-02-14T10:03:40","modified_gmt":"2025-02-14T10:03:40","slug":"new-device-code-phishing-attack-exploit-device-code-authentication-to-capture-authentication-tokens","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/14\/new-device-code-phishing-attack-exploit-device-code-authentication-to-capture-authentication-tokens\/","title":{"rendered":"New Device Code Phishing Attack Exploit Device Code Authentication To Capture Authentication Tokens"},"content":{"rendered":"<p>    New Device Code Phishing Attack Exploit Device Code Authentication To Capture Authentication Tokens<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated phishing campaign, identified by Microsoft Threat Intelligence, has been exploiting a technique known as \u201cdevice code phishing\u201d to capture authentication tokens.<\/p>\n<p>This attack, attributed to a group called Storm-2372, has been active since August 2024 and targets a wide range of industries and governments globally.<\/p>\n<p>The campaign uses a <a href=\"https:\/\/cybersecuritynews.com\/cisa-fbi-details-phishing-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing technique<\/a> that tricks users into logging into productivity apps, allowing the attackers to capture authentication tokens that can be used to access compromised accounts.<\/p>\n<p>Device code authentication is a method used to authenticate accounts from devices that cannot perform interactive web-based authentication.<\/p>\n<p>Security experts at Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/02\/13\/storm-2372-conducts-device-code-phishing-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that it involves entering a numeric or alphanumeric code on a separate device to sign in. In device code phishing, attackers generate a legitimate device code request and deceive targets into entering it on a legitimate sign-in page.<\/p>\n<p>This grants the attackers access to authentication and refresh tokens, which they can use to access the target\u2019s accounts and data without needing a password.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgmElQ3cxyDOxHxsSt8tQ49jZSd53-vbIGkULg_pWeSqDe-Er3y1GSjArzY4A8vZIqFS9EkVHIqRlZvq3sWOYTv5_TrrvualX8JQ9zdZ5Xg3Sc_jmAVHEUy0OWLHJJLMPCuzaZt1RBaMZiyMh4AI5B0nYABmfmFW3d-QPTI7x_wX-N1__wOSqqy6152WlY\/s16000\/Device%2520code%2520phishing%2520attack%2520cycle%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Device code phishing attack cycle (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Storm-2372\u2019s Tactics<\/strong><\/h2>\n<p>Storm-2372\u2019s campaign involves creating lures that resemble messaging app experiences, such as WhatsApp, Signal, and <a href=\"https:\/\/cybersecuritynews.com\/microsoft-teams-recordings\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Teams<\/a>.<\/p>\n<p>The attackers pose as prominent individuals to build rapport with targets before sending phishing emails that appear to be meeting invitations.<\/p>\n<p>These invitations prompt users to authenticate using a device code, which the attackers use to capture valid access tokens.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj7nrrbn-oZ2cSIEvyJ8BXhxovYiiZa8mHtoP4Jrm5mTUpCO0UakoFiBN-qnTQ7QBfEB5MFAqDbX6HCxLdfYAaeFnuXQm5jQP5Ru0Bn_bBPSPjuTpbDJ63Nw_SzBtTnUN3bbTyUM_oZwbrL0djsqMdYIC3L9LW6pTv1esVwaVU0MSOeJnms3gkK-fpmnrw\/s16000\/Sample%2520Messages%2520from%2520the%2520Threat%2520Actor%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Sample Messages from the Threat Actor (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p>After obtaining access tokens, Storm-2372 uses them to move laterally within compromised networks and harvest emails using Microsoft Graph.<\/p>\n<p>The attackers search for keywords like \u201cusername,\u201d \u201cpassword,\u201d and \u201ccredentials\u201d in compromised accounts.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh86cpZP4h5BmTunHGpRHkhnEaS1UNKaBYchn6vyEBux3mO72eNcZprKlver75HonSmqZ9e0V2UAlZb2JkkXgZpUp_J81383io6K9k53rFiCdQZJaPedOycy1aL9NrlIvO1hWytS_Kie1DunWeFEekP8MR0cE4-0xzZ0IaLhwLMk21cfLoju3CPCUu0k_U\/s16000\/Example%2520of%2520Lure%2520Used%2520in%2520Phishing%2520Campaign%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Example of Lure Used in Phishing Campaign (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p>Example Hunting Query for Microsoft Defender XDR:-<\/p>\n<pre class=\"wp-block-code\"><code>let suspiciousUserClicks = materialize(UrlClickEvents\n    where ActionType in (\"ClickAllowed\", \"UrlScanInProgress\", \"\u2026\")\n    where UrlChain has_any (\"microsoft.com\/devicelogin\", \"login\u2026\")\n    extend AccountUpn = tolower(AccountUpn)\n    project ClickTime = Timestamp, ActionType, UrlChain, Network\u2026<\/code><\/pre>\n<p>To defend against device code phishing attacks, organizations should restrict the use of device code flows, educate users on phishing tactics, and enforce strong <a href=\"https:\/\/cybersecuritynews.com\/certificate-based-authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication measures<\/a> such as MFA and phishing-resistant methods like FIDO Tokens.<\/p>\n<p>Implementing Conditional Access policies to monitor risky sign-ins and centralizing identity management can further enhance security.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/analysis\/lookup?utm_source=csn_feb&amp;utm_medium=article&amp;utm_campaign=ti&amp;utm_content=lookup-tasks-1&amp;utm_term=120225\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-device-code-phishing-attack-exploit-device-code-authentication\/\">New Device Code Phishing Attack Exploit Device Code Authentication To Capture Authentication Tokens<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-device-code-phishing-attack-exploit-device-code-authentication\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Device Code Phishing Attack Exploit Device Code Authentication To Capture Authentication Tokens A sophisticated phishing campaign, identified by Microsoft Threat Intelligence, has been exploiting a technique known as \u201cdevice code phishing\u201d to capture authentication tokens. This attack, attributed to a group called Storm-2372, has been active since August 2024 and targets a wide range [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,63,700],"tags":[130],"class_list":["post-1983","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-security-news","category-cyberattack-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1983"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1983"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1983\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1983"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1983"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1983"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}