eSentire’s Threat Response Unit said it detected the active campaign in late August, with operators using business-email social engineering rather than conventional fake login pages. Attackers posed as procurement staff from legitimate organisations, including BJ’s Wholesale Club, and used Salesforce contact forms to submit apparently harmless sales enquiries before continuing conversations by email.
The campaign then moved victims through a chain that included WeTransfer links and password-protected HTML files presented as business documents. The lure masqueraded as a document-sharing service called FlipBook and used layered obfuscation, including encrypted redirect logic, before sending targets through bot checks and a Cloudflare Turnstile challenge.
Victims were ultimately directed to Microsoft’s legitimate device authentication page, where they were asked to enter a Microsoft-issued user code and complete their normal sign-in, including multifactor authentication. Because the page and authentication process were genuine, the attackers did not need to collect the victim’s password directly.
GhostCode abused the OAuth 2.0 device authorisation grant, a Microsoft-supported flow intended for devices with limited input capabilities such as smart televisions, printers and some shared devices. Under the legitimate process, a device obtains a code, while the user completes authentication in a separate browser and the device polls Microsoft for tokens after approval.
eSentire said the attackers used the Microsoft Authentication Broker application identity and requested access that included Microsoft Graph and offline access. Once the victim approved the device-code request, the phishing infrastructure polled for successful authentication and used the resulting token almost immediately.
The researchers recorded nine successful API calls within 78 seconds of authentication. During that period, the operators registered three devices in Microsoft Entra, completed an Intune enrolment and accessed Microsoft Graph. A Primary Refresh Token was obtained 32 seconds after the initial authentication, giving the attacker a stronger foothold than a single stolen session token.
The key persistence issue was device registration. eSentire said each rogue device remained recorded in the victim organisation’s tenant until explicitly disabled or removed. Revoking the original compromised token did not by itself remove those device records, while registering three devices created multiple persistence paths.
After confirming the compromise, the security team revoked the token grant, reset the affected account’s credentials and disabled all three attacker-enrolled devices. Attempts made after revocation failed, but the researchers said Intune enrolment itself survives token revocation unless administrators separately remove or disable the device.
The campaign also rotated residential proxy addresses, largely within the United Kingdom, to keep activity geographically consistent with the victim’s location. eSentire said eight of nine successful requests originated from UK residential internet providers, while the final Intune enrolment came from an address in Frankfurt associated with GHOSTnet GmbH.
That behaviour was significant because Microsoft’s device authentication screen can display the location associated with the request. Matching the victim’s country could make the prompt appear less suspicious, while rotating residential addresses may also reduce the effectiveness of controls based on unfamiliar locations or individual IP reputation.
Microsoft classifies device-code flow as a higher-risk authentication method because attackers can initiate the flow and persuade users to approve it on a legitimate Microsoft page. Its guidance recommends blocking device-code authentication wherever possible and restricting it through Conditional Access when organisations still require it for specific equipment or workflows.
Microsoft also advises administrators to review sign-in logs before enforcement, identify legitimate uses and keep exceptions tightly scoped. Some Teams devices, command-line tools and specialised provisioning processes can depend on device-code authentication, making an indiscriminate block operationally disruptive in certain environments.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.