Device code phishing abuses the OAuth 2.0 device authorization grant to bypass MFA. The attacker initiates a genuine device-code request with Microsoft, delivers the code to a victim via a convincing phishing lure, and the victim authenticates on the real Microsoft sign-in page — satisfying MFA legitimately. Microsoft then issues tokens to the attacker's server rather than the victim. The attacker uses these tokens to register rogue devices, create hidden inbox rules, and send further phishing from the compromised mailbox, all without touching the victim's endpoint.
OAuth 2.0
1 post
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass