Executive Summary
In late August 2026, security researchers identified a sophisticated phishing campaign utilizing a novel kit dubbed 'GhostCode'. This kit specifically targets the OAuth 2.0 device authorization grant flow (RFC 8628), a mechanism designed for browserless devices that threat actors are now leveraging to compromise enterprise Microsoft 365 accounts. By tricking victims into entering an attacker-supplied user code into Microsoft's legitimate sign-in page, the kit bypasses Multi-Factor Authentication (MFA) and grants the adversary long-lived tokens.
The attack chain typically begins with social engineering via web contact forms, posing as procurement officers to establish trust. The subsequent technical stages employ multi-layered evasion, including junk padding, character-level comment injection, and AES-256-GCM encryption of redirect URLs. Once authentication is successful, the kit is capable of rapid automated persistence; in observed cases, attackers registered multiple rogue devices and obtained a Primary Refresh Token (PRT) in under 80 seconds.
This threat is particularly significant because traditional MFA does not provide protection once the device code is authorized. Organizations are at risk of Single Sign-On (SSO) equivalent access theft, allowing adversaries to harvest emails, enroll rogue MDM devices, and maintain persistence even after initial password resets.
Key Details
Threat Name
GhostCode Phishing Kit
Affects
N-able N-central RMM platform, PaperCut NG, PaperCut MF Application Servers, Progress Telerik UI for ASP.NET AJAX
Adversary
Storm-2372 Other Adversaries and Aliases: FIN7; Lazarus
MITRE Techniques
Malware/Tools
GhostCode, EvilTokens
