Tag
#Phishing
GhostCode Phishing Kit Abuses Microsoft OAuth Device Authorization Flow
A new phishing kit, GhostCode, is being used to trick Microsoft 365 users into handing over access to their accounts by exploiting a weakness in Microsoft's OAuth 2.0 device authorization grant flow. This campaign, identified in late August 2026, uses social-engineering tactics to convince victims to enter a device code on Microsoft's authentication page, allowing attackers to obtain authentication tokens and establish persistence in the victim's Microsoft environment. Security professionals should be aware of this threat and take steps to mitigate it.
Malicious Infrastructure Distributes EtherRAT and Phishing Pages
Researchers discovered a vast network of malicious infrastructures distributing EtherRAT malware, phishing pages, and malicious software. The malware was initially found on a website with a suspicious homepage.