GhostCode: Novel Microsoft Device Code Phishing Kit
Score: 9/10

GhostCode: Novel Microsoft Device Code Phishing Kit

GhostCode is a novel phishing kit that abuses the Microsoft Device Code authorization flow to bypass MFA and achieve persistent access to M365 environments.

Executive Summary

In late August 2026, security researchers identified a sophisticated phishing campaign utilizing a novel kit dubbed 'GhostCode'. This kit specifically targets the OAuth 2.0 device authorization grant flow (RFC 8628), a mechanism designed for browserless devices that threat actors are now leveraging to compromise enterprise Microsoft 365 accounts. By tricking victims into entering an attacker-supplied user code into Microsoft's legitimate sign-in page, the kit bypasses Multi-Factor Authentication (MFA) and grants the adversary long-lived tokens.

The attack chain typically begins with social engineering via web contact forms, posing as procurement officers to establish trust. The subsequent technical stages employ multi-layered evasion, including junk padding, character-level comment injection, and AES-256-GCM encryption of redirect URLs. Once authentication is successful, the kit is capable of rapid automated persistence; in observed cases, attackers registered multiple rogue devices and obtained a Primary Refresh Token (PRT) in under 80 seconds.

This threat is particularly significant because traditional MFA does not provide protection once the device code is authorized. Organizations are at risk of Single Sign-On (SSO) equivalent access theft, allowing adversaries to harvest emails, enroll rogue MDM devices, and maintain persistence even after initial password resets.

Key Details

Threat Name

GhostCode Phishing Kit

Affects

N-able N-central RMM platform, PaperCut NG, PaperCut MF Application Servers, Progress Telerik UI for ASP.NET AJAX

Adversary

Storm-2372 Other Adversaries and Aliases: FIN7; Lazarus

Malware/Tools

GhostCode, EvilTokens

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance8
Enterprise Relevance10
Clarity & Structure9
Technical Depth9

Sources