
Cybersecurity experts are raising awareness about an ongoing phishing scheme using device codes to compromise Microsoft 365 accounts in over 340 organizations across the U.S., Canada, Australia, New Zealand, and Germany.
Huntress reported that this activity was initially detected on February 19, 2026, and has since increased rapidly. The campaign is using Cloudflare Workers to redirect captured sessions to a platform-as-a-service (PaaS) called Railway, effectively using it as a credential harvesting mechanism.
The campaign is prominently targeting sectors like construction, non-profits, real estate, manufacturing, financial services, healthcare, legal, and government.
“This campaign is unusual due to both the device code phishing methods used and the variety of techniques employed,” the company stated. “Construction bid scams, landing page code generation, DocuSign spoofing, voicemail alerts, and abuse of Microsoft Forms pages are all targeting the same victims through the same Railway.com IP infrastructure.”
Device code phishing is a technique that exploits the OAuth device authorization flow to give attackers long-term access tokens, which can be used to take over accounts. A key feature of this attack is that the tokens remain valid even if the account password is changed.
Here’s a simplified explanation of how the attack works:
“Once the user is tricked, their authentication creates tokens that are stored at the OAuth token API endpoint and can be accessed by providing the correct device code,” Huntress explained. “The attacker knows the device code because they generated it with the initial cURL request to the device code login API.”
“So, while the code is useless on its own, once the victim authenticates, the resulting tokens are accessible to anyone who knows the device code used in the initial request.”
Microsoft and Volexity first observed device code phishing in February 2025, with subsequent waves reported by Amazon Threat Intelligence and Proofpoint. These attacks have been attributed to multiple Russian-linked groups, including Storm-2372, APT29, UTA0304, UTA0307, and UNK_AcademicFlare.
The technique is sneaky because it uses legitimate Microsoft systems to perform the device code authentication, giving users no reason to believe anything is wrong.
In the campaign Huntress detected, the authentication abuse originates from a small set of Railway.com IP addresses, with three of them responsible for about 84% of the observed activity:
The attack begins with a phishing email containing malicious URLs wrapped within legitimate security vendor redirect services from Cisco, Trend Micro, and Mimecast to bypass spam filters. This triggers a series of redirects involving compromised sites, Cloudflare Workers, and Vercel before the victim reaches the final destination.
“The landing pages prompt the victim to go to the legitimate Microsoft device code authentication endpoint and enter a provided code to view files,” Huntress said. “The code is displayed directly on the page when the victim arrives.”
“This is a unique take on the tactic, as typically the attacker must generate and provide the code to the victim. By displaying the code directly on the page, likely through automated code generation, the victim immediately receives the code and the reason for the attack.”
The landing page also has a “Continue to Microsoft” button that opens a pop-up window displaying the legitimate Microsoft authentication endpoint (“microsoft[.]com/devicelogin”).
Almost all device code phishing sites have been hosted on a Cloudflare workers[.]dev instance, showing how the attackers are exploiting the trust associated with the service in business environments to bypass web content filters. To defend against this threat, users should scan sign-in logs for Railway IP logins, revoke refresh tokens for affected users, and block authentication attempts from Railway infrastructure if possible.
Huntress has since linked the Railway attack to a new phishing-as-a-service (PhaaS) platform called EvilTokens, which launched last month on Telegram. In addition to advertising tools for sending phishing emails and bypassing spam filters, the EvilTokens dashboard offers customers open redirect links to vulnerable domains to hide the phishing links.
“Besides rapidly adding new features, the EvilToken team has established a full 24/7 support team and a support feedback channel,” the company said. “They also gather customer feedback.”
This disclosure follows a warning from Palo Alto Networks Unit 42 about a similar device code phishing campaign. They highlighted the attack’s use of anti-bot and anti-analysis methods to avoid detection while stealing browser cookies. The earliest observation of this campaign dates back to February 18, 2026.
The phishing page “disables right-click functionality, text selection, and drag operations,” the company said, adding that it “blocks keyboard shortcuts for developer tools (F12, Ctrl+Shift+I/C/J) and source viewing (Ctrl+U)” and “detects active developer tools by using a window size check, which then starts an infinite debugger loop.”
#340 #365 #abuse #across #attacks #code #countries. #device #enables #five #impacting #microsoft #news #oauth #organizations #over #phishing — News
© Bulletproof Servers. All rights reserved.