OAuth device-code phishing campaign targeting SaaS accounts
Campaign
Summary
Hide ▲
Show ▼
A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hijack Microsoft accounts and steal access tokens and refresh tokens for persistent access and BEC. Sekoia reported that the infrastructure had global reach, with the most affected countries including the United States, Canada, France, Australia, India, Switzerland, and the UAE, and the operator says support for Gmail and Okta phishing pages is planned.
Related Happenings
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
Campaign
H score37
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
CampaignAbout this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
ShinyHunters-linked Salesforce intrusion campaign
Campaign
H score45
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
ShinyHunters-linked Salesforce intrusion campaign
CampaignAbout this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
Microsoft Entra OAuth Client ID spoofing campaign
Campaign
H score58
First: 13.07.2026 16:00
Last: 13.07.2026 16:00
Sources 1
About this happening:
A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft Entra OAuth Client ID spoofing campaign
CampaignAbout this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Timeline
-
04.04.2026 17:17 4 articles · 3mo ago
Device code phishing campaign expands across SaaS-themed phishing kits
Campaign Scope UpdatePush Security reported that device code phishing abusing the OAuth 2.0 Device Authorization Grant flow had risen 37.5x this year, with EvilTokens identified as a major driver and at least 11 kits circulating across SaaS-themed lures and cloud-hosted infrastructure. Sekoia separately published research on EvilTokens earlier that week, and Push recommended disabling device-code flow where unnecessary through conditional access policies and monitoring for unexpected device code authentication events, unusual IP addresses, and unfamiliar sessions.
Show sources
- Device code phishing attacks surge 37x as new kits spread online — www.bleepingcomputer.com — 04.04.2026 17:17
- Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing — www.darkreading.com — 17.04.2026 22:05
- New EvilTokens service fuels Microsoft device code phishing attacks — www.bleepingcomputer.com — 01.04.2026 22:42
- New Ghost Phishing Wave Is Breaking Traditional Email Security — thehackernews.com — 08.07.2026 16:00