Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique into an industrial-scale threat in 2026. Originally designed for input-constrained devices like smart TVs and printers, the device code flow is now widely used for CLI logins, making it an attractive target for attackers.
Nation-state actors like Storm-2372 began exploiting this vector in 2024, followed by ShinyHunters’ large-scale campaign against Salesforce in 2025. The release of the EvilTokens kit in February 2026 marked a turning point, leading to a surge in criminal adoption. Microsoft now reports 10 to 15 new campaigns daily, and Barracuda detected 7 million attacks in just four weeks. The FBI issued a rare advisory on the Kali365 phishing kit, highlighting the severity of the threat.
Device code phishing bypasses all forms of MFA, including passkeys, because it targets the authorization layer after authentication has already succeeded. The phishing-as-a-service (PhaaS) ecosystem has fully industrialized the technique, with kits like Tycoon2FA and Kali365 integrating it into their platforms. Attackers are using AI-assisted development to create new kits faster than defenders can catalog them, with over 25 distinct kits already tracked by Push Security.
While 99% of current attacks target Microsoft, the cross-platform nature of the OAuth 2.0 device authorization grant means platforms like GitHub, AWS, and Salesforce are also vulnerable. The shift toward authorization attacks is broader, with techniques like ConsentFix also targeting the authorization layer. Detection requires visibility at the browser level, where both the phishing lure and the device code approval can be observed. Push Security’s agentic threat hunting pipeline offers a proactive approach to detecting these attacks across any provider.
CVEs: CVE-2026-50522
Attack groups: Storm-2372, ShinyHunters
Malware: EvilTokens, Kali365, Tycoon2FA, ARToken, ConsentFix
Companies: Microsoft, Salesforce, GitHub, AWS, Barracuda, Push Security
Original source: thehackernews.com