MFA Fails to Stop Theft
GhostCode Hijacks Microsoft 365 Accounts
- GhostCode abuses device codes to hijack Microsoft 365 accounts
- Three devices registered within 78 seconds
- Attackers steal tokens after successful MFA approval
A new phishing kit is turning legitimate Microsoft 365 sign-in pages into a tool for account theft. Named GhostCode, the kit abuses Microsoft’s device authorization process instead of stealing passwords. Victims complete multi-factor authentication on a genuine Microsoft page but unknowingly authorize an attacker-controlled device to access their work account. According to eSentire’s analysis, attackers registered three devices within just 78 seconds in one observed case.
eSentire analysts identified the activity in late August. The researchers named the kit GhostCode after its hidden code and the GHOSTnet system used during device setup.
Attack Starts with Business Messages
The campaign begins with ordinary messages sent through business contact forms. Attackers pose as procurement employees and ask targets to sign a non-disclosure agreement. They then send a WeTransfer link containing a password-protected HTML file.
The file presents what appears to be a document-sharing process and instructs the target to sign in using a Microsoft device code.
The victim then visits a real Microsoft page and approves the code. However, the approval actually gives the attacker’s device access to the victim’s Microsoft 365 account.
This makes the attack particularly difficult to detect. The victim does not have to enter a password into a fake login page. Instead, they complete the normal authentication process themselves, including MFA.
GhostCode Abuses OAuth
GhostCode abuses the OAuth device authorization flow. Microsoft designed this process for devices such as smart televisions that cannot easily display a full sign-in screen.
The attacker’s server requests a code using the Microsoft Authentication Broker application identity. The code is placed inside a fake document portal, and the target is instructed to approve it on Microsoft’s website.
Once approved, the attacker’s device receives authorization to access the account.
The HTML attachment is also designed to resist inspection. It contains excess data, hides visible text with HTML comments and conceals the redirect address until the correct password is entered.
Detection Systems Can Be Filtered
After a victim reaches the phishing server, browser tests and location checks help filter automated scanners and analysis systems. The technique resembles activity previously associated with the EvilTokens phishing service, but GhostCode combines it with targeted outreach through business contact forms.
After successful authentication, the attackers use residential proxy addresses selected to match the victim’s location. This can make the Microsoft prompt appear less unusual and may reduce some location-based security alerts.
eSentire found that the attackers made nine successful API calls, registered three devices within 78 seconds and obtained a Primary Refresh Token within 32 seconds.
The token can allow access to Microsoft 365 services without requiring the user to authenticate again each time. This means attackers can begin operating inside the account before the victim realizes that access has been compromised.
Security Teams Need New Signals
Organizations are advised to use device-based access policies where appropriate. Security teams should also monitor successful device-code events followed by unusual scripted requests or multiple device registrations from a single session.
Suspicious device names should also be investigated, particularly names that combine a user’s first name, last name, company domain and a hexadecimal pattern.
The sequence of events can be an important detection signal. A successful device-code approval followed by unusual API activity or multiple device registrations may indicate an account takeover attempt.
User awareness remains important. Employees should treat unexpected requests to copy or approve a device code on a Microsoft page as suspicious, particularly when the request comes through an unfamiliar business contact and is linked to a document or non-disclosure agreement.
GhostCode demonstrates how modern phishing campaigns are increasingly targeting authentication tokens and authorization flows rather than passwords. The use of a legitimate identity page can make the attack appear normal to the user while giving attackers access to cloud accounts.
//DBTech/SME/SIF//





