CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

July 7, 2026

A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed lures to bypass multi-factor authentication (MFA). The campaign, analyzed by ZeroBEC, uses a reusable tooling layer called DEBULL, which shares strong overlaps with the Storm-2372 campaign documented by Microsoft in February 2025.

Device code phishing exploits the legitimate OAuth 2.0 Device Authorization Grant flow, designed for devices with limited interfaces. Attackers initiate the authentication flow, share the generated code with victims via phishing lures, and trick them into entering it on a legitimate Microsoft login page. This grants the attacker access to the victim’s account without requiring passwords or triggering MFA.

ZeroBEC’s investigation reveals that DEBULL is likely a phishing-as-a-service (PhaaS) platform using GraphSpy or a GraphSpy-derived workflow for post-exploitation. The campaign uses payment and shared-folder pretexts in emails, leading victims to a compromised Croatian rental website that orchestrates the device code challenge. The infrastructure includes Turkish-language developer markers, though attribution remains uncertain.

The disclosure also highlights a surge in device code phishing, with other PhaaS kits like EvilTokens, Tycoon 2FA, and ARToken adopting similar techniques. Cisco Talos identified ARToken as a fully-featured operator panel with over 80 API endpoints for device code phishing, PRT persistence, email access, BEC operations, and SharePoint exfiltration. These platforms enable attackers to automate BEC workflows, exfiltrate sensitive data, and maintain persistent access to compromised accounts.

CVEs: CVE-2026-55200, CVE-2026-46817

Attack groups: Storm-2372

Malware: DEBULL, GraphSpy, EvilTokens, Tycoon 2FA, ARToken

Companies: Microsoft, ZeroBEC, Cisco Talos, Proofpoint, Huntress, eSentire

Products: Microsoft 365, Microsoft Authentication Broker, Microsoft Graph API, Microsoft Entra, OneDrive, SharePoint, ARTBrowser, Trustifi