VMTech
Discuss a project

Device code phishing surges as OAuth authorization attacks scale

Device code phishing surges as OAuth authorization attacks scale

On July 31, 2026, Push Security said device code phishing had become an industrial-scale threat in under six months. By April, Microsoft was seeing 10 to 15 new campaigns every 24 hours, Barracuda had counted 7 million attacks in four weeks, and Push was tracking more than 25 kits.

Why established controls miss the attack

The technique abuses the OAuth 2.0 device authorization grant, designed for input-constrained hardware. A victim enters a short code on the provider’s legitimate device-login page, selects an authenticated account and approves access. The attacker receives tokens without breaking the login process.

This separation between authentication and authorization is the central risk. Passkeys, hardware keys and phishing-resistant MFA may all work correctly while malicious access is still granted. Email gateways, proxies and URL reputation tools also have limited visibility because approval occurs on trusted infrastructure.

Criminal tooling broadens the target set

Adoption accelerated after Storm-2372 used the technique in 2024, ShinyHunters targeted Salesforce tenants in 2025, and EvilTokens appeared in February 2026. Kali365 and Tycoon2FA now package device-code capabilities alongside adversary-in-the-middle phishing. This commercialization echoes the expansion of Kali365 MFA bypass campaigns, while ARToken adds token persistence, mailbox access, business email compromise automation and SharePoint exfiltration.

Push links the growth in kit families partly to AI-assisted development. Independently built tools can share layouts and code structures because their creators use similar LLM prompts, allowing new variants to appear faster than defenders can catalog domains and fixed indicators.

Microsoft represents 99% of Push detections today, but the standard is cross-platform. Push says the ShinyHunters Salesforce campaign affected more than 1,000 organizations and exposed 1.5 billion records. GitHub and AWS also support device flows used by CLI tools and developer workflows.

Businesses should govern token grants as closely as sign-ins: restrict device-code authentication where feasible, inventory legitimate CLI and constrained-device use, monitor unusual consent and token activity, and add browser-level behavioral detection. Blocking every flow may disrupt development, but MFA alone does not close the authorization gap.

#oauthsecurity#phishing#identitysecurity#browsersecurity
Open analytics
On the site 0 views
min read 3 31.07.2026
Instagram

Device code phishing surges as OAuth authorization attacks scale

Open the post on Instagram ↗