Most Popular ShinyHunters 2026 Detection: OAuth Device Code Phishing via Malicio
Detects unauthorized abuse of the OAuth 2.0 device authorization grant flow in Salesforce environments, commonly used by threat actors like ShinyHunters (UNC6240) to gain programmatic access. Attackers register malicious connected apps to impersonate legitimate tools, then use social engineering (vishing) to trick victims into approving device codes. This rule flags token issuance from non-allowlisted connected apps using the device_code grant type.
Sigma

