Attackers Abuse Device Codes to Bypass Microsoft 365 MFA

Attackers Abuse Device Codes to Bypass Microsoft 365 MFA

Security protocols that once seemed invincible are now being systematically dismantled by adversaries who have shifted their focus from stealing passwords to hijacking legitimate authenticated sessions via the OAuth 2.0 device code flow. This protocol was originally engineered to facilitate logins on devices with constrained input interfaces, such as smart televisions or office printers, where typing a complex password is a cumbersome task. In a standard legitimate scenario, a device generates a unique alphanumeric code that a user then enters into a trusted Microsoft website using a more capable secondary device like a smartphone or laptop. However, modern threat actors have discovered that by initiating this request themselves, they can effectively trick unsuspecting employees into authorizing an active session directly on a remote attacker-controlled machine. This method completely circumvents traditional multi-factor authentication because the user is performing the validation themselves.

Strategic Deception: The Art of Building False Trust

Building a foundation for such a sophisticated breach often requires more than just a malicious link; it necessitates a high degree of psychological manipulation known as rapport building. Rather than deploying high-volume, generic phishing campaigns that are easily flagged by modern filters, these specialized attackers spend days or even weeks masquerading as legitimate business partners or legal counsel. They engage in innocuous conversations, discussing ongoing projects or upcoming contracts to lower the target’s natural defenses and establish a sense of professional familiarity. This ‘slow-play’ strategy ensures that when the attacker finally provides a link to what is described as an urgent document portal, the victim is significantly more likely to follow the instructions without hesitation. By the time the request for a device code entry appears, the victim has already been conditioned to trust the source, making them a willing participant in their own compromise.

Multi-Stage Delivery: Bypassing Advanced Security Filters

To ensure these malicious communications reach their destination, the campaign utilizes a multi-stage delivery infrastructure designed to evade advanced email security gateways and sandboxing tools. Adversaries frequently host their initial landing pages on reputable platforms like Google Sites or leverage compromised redirectors on well-known corporate websites to mask the final destination of the traffic. By using these trusted domains, they exploit the inherent reputation of the host, making the link appear safe to automated scanners that might otherwise block a fresh, unrecognized URL. Furthermore, many of these phishing sites now incorporate ‘human-check’ prompts, such as CAPTCHAs, which serve a dual purpose in the attack chain. While they frustrate automated security bots that attempt to crawl the site for malicious content, they simultaneously enhance the perceived legitimacy of the page for the user, who has been trained to associate such checks with secure portals.

Technical Execution: Hijacking Official Authentication Portals

The technical brilliance of this specific attack vector lies in its reliance on the authentic Microsoft login ecosystem rather than a clumsy imitation of a login page. When a victim follows the instructions on a phishing site, they are directed to the official Microsoft device login URL to enter the code provided by the attacker. Because the user is interacting with a genuine, verified domain and potentially completing a standard multi-factor authentication challenge on their own mobile device, traditional endpoint security tools often fail to generate any meaningful alerts. The platform views the interaction as a legitimate user-initiated sign-in from a new device, and once the code is entered, the resulting session tokens are transmitted directly to the attacker’s command-and-control server. This allows the adversary to bypass the need for credentials entirely, gaining immediate access to the victim’s entire suite of cloud applications and sensitive corporate data stores.

Persistent Footholds: Rogue Devices and Mailbox Rules

Once an attacker has successfully hijacked a session, their immediate priority shifts toward establishing a permanent foothold that can survive password resets or session expirations. A common tactic involves the registration of a ‘rogue’ device within the corporate environment, which allows the threat actor to maintain continuous access and satisfy future conditional access requirements. Simultaneously, they often implement hidden mailbox rules that are designed to keep the victim in the dark about the ongoing intrusion. These rules automatically redirect or delete security notifications, such as alerts regarding new device registrations or sign-ins from unusual locations, and can even hide replies from colleagues who might be questioning suspicious activities. By managing the inbox in this way, the adversary can operate silently for extended periods, carefully exfiltrating data or preparing for the next phase of the operation without triggering the internal alarms that usually follow a breach.

Internal Expansion: The Danger of Lateral Movement

A single compromised account frequently serves as a powerful staging ground for lateral movement across the entire organizational network or even into the environments of external partners. Because emails sent from a legitimate internal account are rarely scrutinized with the same level of skepticism as external messages, attackers can distribute internal phishing lures with an exceptionally high success rate. This allows the threat to propagate rapidly, as colleagues are likely to click on links or download attachments sent by a known coworker. Such internal expansion often leads to the compromise of administrative accounts or the exfiltration of high-value intellectual property that is normally protected by strict external barriers. The resulting data breach can be far more extensive than a typical single-user compromise, as the attacker essentially leverages the internal trust hierarchy to bypass security layers that were never designed to defend against a verified, authenticated insider.

Future Mitigation: Implementing Phishing-Resistant Standards

Defending against the abuse of device-code flows required a fundamental shift toward more proactive identity monitoring and the implementation of much stricter access control policies. Security teams began prioritizing the total deactivation of the device-code flow for the vast majority of the workforce, ensuring that this specific gateway remained closed except for the few users who actually required it for specialized hardware. Furthermore, organizations integrated advanced cloud-based identity protection tools that monitored for ‘impossible travel’ alerts and the sudden creation of unusual mailbox rules which often signaled an active session hijack. The most effective long-term solution involved the deployment of phishing-resistant multi-factor authentication, such as FIDO2 security keys, which effectively tied the authentication process to the specific hardware and browser session. By adopting these rigorous standards, companies significantly reduced their attack surface and moved toward a more resilient security posture.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later