Device Code Phishing: The Fastest-Growing Threat of 2026 and How to Defend Against It
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
A recent EvilTokens campaign is exploiting a new 'ghost phishing' technique that hides malicious content until it decrypts inside the victim's browser,…
EvilTokens is an attack group conducting ghost phishing campaigns targeting US and European businesses. They use Microsoft Device Code Phishing and AES-GCM…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
EvilTokens is a phishing kit released in February 2026 that significantly lowered the barrier to entry for device code phishing. Its availability…