21.5 C
New York
September 19, 2026
Worship Media
Technology

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

The attackers also employed multiple evasion techniques, including padding and obfuscating the HTML code in their lure, encrypting redirects, checking for bots, and using Cloudflare Turnstile to keep security tools away from the phishing page.

What defenders can do

To defend against attacks like this, eSentire’s researchers recommend restricting Microsoft’s device-code authentication flow through Conditional Access and disabling it for users who do not need it. It also advises monitoring the Device Registration Service for multiple device registrations from a single non-interactive session, and looking for activity involving the user agent python-requests following device-code authentication.

Auditing Entra ID for devices matching GhostCode’s naming pattern and correlating successful device-code authentication with subsequent Python-based requests, should be able to catch an attack in progress, the company said. It shared a list of indicators of comprise related to the campaign to aid detection.

Click Here to Visit Orignal Source of Article https://www.computerworld.com/article/4223889/ghostcode-attackers-abuse-device-codes-to-take-over-microsoft-365-accounts.html

Related posts

How social media will become the most reliable source of information

ComputerWorld

Apple deepens its engagement in enterprise security

ComputerWorld

Flashback Friday: It was like this when I got here

ComputerWorld

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More

Privacy & Cookies Policy