PULSE NAME
Device Code Phishing is an Evolution in Identity Takeover
WHITE TA4903 AlienVault 2026-05-14 Modified: 2026-05-14
35
IOCs
MEDIUM VOLUME
Device code phishing attacks have exploded across the threat landscape, with new toolkits emerging weekly. This surge coincides with publicly released criminal toolkits and multiple phishing-as-a-service offerings like EvilTokens and Tycoon. Threat actors abuse the OAuth 2.0 device authorization grant flow to compromise Microsoft 365 and other enterprise accounts by tricking users into authorizing malicious applications. Current implementations use on-demand code generation, addressing the 15-minute expiration limitation of previous techniques. Most activity appears to be generated using AI-based coding techniques. Successful attacks lead to full account takeover, data theft, business email compromise, and potential ransomware deployment. The technique represents the natural evolution of credential phishing as organizations improve their defenses against traditional multifactor authentication bypass methods.
Indicators of Compromise (33 / 35 total)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain 019d442a-endpoint.com 2026-05-14
domain 019d442e-endpoint.com 2026-05-14
domain 019d6860-endpoint.com 2026-05-14
domain 0fdba029e6a5-endpoint.com 2026-05-14
domain 2dc62559e005-endpoint.com 2026-05-14
domain 4daa2aea93db-endpoint.com 2026-05-14
domain 6dd5fd945b34-endpoint.com 2026-05-14
domain 7806d4cf9366-endpoint.com 2026-05-14
domain consistentdigital.de 2026-05-14
domain crediblebizextension.de 2026-05-14
domain digitalcontinuity.de 2026-05-14
domain digitalreliability.de 2026-05-14
domain ed5ce47d835f-endpoint.com 2026-05-14
domain ee10bbf6c689-endpoint.com 2026-05-14
domain euromarketsignal.de 2026-05-14
domain europesignaltrust.de 2026-05-14
domain europetrustwave.de 2026-05-14
domain extendyourcredibility.de 2026-05-14
domain f36c2774f013-endpoint.com 2026-05-14
domain heilbronner-fruehlingssymposium.de 2026-05-14
domain jo2c9ada427c6-endpoint.com 2026-05-14
domain kohlhoff-edelstahlverarbeitung.de 2026-05-14
domain marketcredibilitysignals.de 2026-05-14
domain marktkarree-langenfeld.de 2026-05-14
domain methodicalness.de 2026-05-14
domain reliableinteractions.de 2026-05-14
domain reliablesupport.de 2026-05-14
domain servicewithoutinterruption.de 2026-05-14
domain stablewebsystems.de 2026-05-14
domain trustedengagement.de 2026-05-14
domain uninterruptedperformance.de 2026-05-14
domain yaga9b286ae2c101-endpoint.com 2026-05-14
domain z6e43e5886fe-endpoint.com 2026-05-14