A significant Microsoft 365 device code phishing campaign has been observed exploiting collaboration-themed lures to compromise victim accounts. The campaign, active from the final week of June 2026 and extending into early July, marks a critical escalation in identity theft tactics, as detailed in recent findings by email security firm ZeroBEC. This particular operation distinguishes itself by foregoing the traditional method of relying on fake Microsoft password pages. Instead, it ingeniously channels users into the legitimate Microsoft device login experience, while a sophisticated backend broker simultaneously generates and polls Microsoft Authentication Broker device-code tokens to hijack sessions.
Understanding Device Code Phishing: A Modern Identity Theft Tactic
Device code phishing represents an advanced form of identity theft that capitalizes on a legitimate OAuth 2.0 authentication mechanism known as the Device Authorization Grant flow. This protocol was originally designed to facilitate secure logins for devices with limited input capabilities, such as smart TVs, gaming consoles, or command-line interface (CLI) tools, where entering a username and password directly might be cumbersome or insecure. In its legitimate application, a user attempting to sign in on such a device is presented with a short, alphanumeric code. The user is then prompted to visit a designated Microsoft web address (e.g., microsoft.com/devicelogin) on a separate, more capable device (like a smartphone or computer) and enter that code to complete the authentication process. This separation of concerns allows for a secure login experience across diverse device types.
However, threat actors have found a potent way to exploit this legitimate separation. Unlike conventional phishing attacks that often involve creating deceptive, look-alike login pages to steal credentials, device code phishing manipulates the user into completing a real, trusted authentication prompt. The attack chain typically unfolds as follows:
- Initiation: The attacker initiates the OAuth 2.0 Device Authorization Grant flow on a legitimate Microsoft domain, generating a unique, short device code.
- Lure Delivery: This code, or a link leading to a page where the code is displayed, is then delivered to the target via a phishing lure. These lures are frequently crafted to appear as urgent collaboration requests, shared document notifications, or payment alerts, often arriving through email or Microsoft Teams messages.
- User Interaction: The unsuspecting victim, believing they are responding to a legitimate request, clicks the provided link. This link directs them to a page instructing them to visit
microsoft.com/deviceloginand input the attacker-generated code. - Unwitting Authorization: When the victim enters the code on the official Microsoft login portal, they unwittingly authorize the attacker’s session.
- Token Acquisition: The attacker’s backend broker, which has been polling for the authorization, then recovers the legitimate access token. This token grants the attacker persistent access to the victim’s account, critically bypassing multi-factor authentication (MFA) without ever needing the user’s password. This makes device code phishing particularly insidious, as MFA is a primary defense against credential compromise.
This sophisticated approach allows threat actors to sidestep many traditional security measures, exploiting trust in official Microsoft domains and the inherent design of the OAuth flow. The method’s effectiveness lies in its ability to leverage legitimate infrastructure, making detection and prevention challenging for both users and automated security systems. The dynamic generation of codes when a user clicks the initial phishing link further enhances the attack’s agility, as noted by Proofpoint in their May 2026 analysis, allowing for highly targeted and timely execution.

The DEBULL Campaign: Unveiling a New Phishing-as-a-Service Toolkit
The campaign identified by ZeroBEC in late June and early July 2026 exhibits "strong" overlaps with the "Storm-2372" campaign, a sophisticated operation first documented by Microsoft in February 2025. Storm-2372 was known for its use of messaging or Teams-style lures to trick victims into entering attacker-provided device codes. While similar in methodology, the current activity suggests threat actors are now employing Storm-2372-style tradecraft through a more formalized and reusable tooling layer dubbed DEBULL.
ZeroBEC’s detailed findings reveal that the recent campaign employed various collaboration-themed pretexts, including payment requests and shared-folder notifications, to entice victims. Upon clicking a malicious URL embedded in these phishing emails, targets were redirected not to a fake login page, but to a legitimate-yet-compromised Croatian rental website. This compromised site served as a "device code orchestrator," initiating the Microsoft device code challenge chain. The orchestrator’s role was to generate the unique device code and guide the victim to the official microsoft.com/devicelogin portal.
Further analysis of the campaign’s infrastructure uncovered several key architectural details. ZeroBEC identified Turkish-language developer markers within the tooling, though this alone is insufficient for definitive attribution to a specific threat group or geographic origin. More significantly, DEBULL appears to function as a full-fledged Phishing-as-a-Service (PhaaS) platform. This platform likely integrates with or utilizes a workflow derived from GraphSpy for Microsoft 365 and Entra post-exploitation activities.
DEBULL offers operators extensive customization options, including the ability to define page names and slugs, directly edit HTML, CSS, and JavaScript, and choose how lures are published. Its embedded templates are particularly crucial, featuring a dedicated Microsoft 365 device-code authentication page, an OAuth callback page, and various modern landing pages. The Microsoft 365 template is central to the attack, providing the exact building blocks required: a user-code display, copy-code functionality, and a direct link to the legitimate Microsoft device login portal. This modularity means that while the front-end lure can be easily changed, the sophisticated backend identity stack remains consistent. This packaging of Storm-2372-style tradecraft into a reusable broker infrastructure like DEBULL significantly lowers the barrier for other cybercriminals to launch sophisticated device code phishing attacks.
The Evolving PhaaS Landscape: ARToken, EvilTokens, and Tycoon 2FA

The emergence of DEBULL is not an isolated incident but rather indicative of a broader and more concerning trend within the cybercrime ecosystem: the increasing sophistication and accessibility of Phishing-as-a-Service (PhaaS) platforms. These platforms democratize advanced attack techniques, enabling less technically proficient criminals to deploy highly effective campaigns. Recent disclosures highlight several other prominent PhaaS kits that are adopting and refining device code phishing.
Cisco Talos recently uncovered ARToken, a fully-featured PhaaS operator panel that shares significant infrastructure, API contracts, and operational patterns with the well-known EvilTokens device code phishing platform. ARToken is made available to affiliates, providing a comprehensive toolkit for illicit operations. Talos researchers detailed ARToken’s extensive capabilities, which include over 80 API endpoints. These endpoints facilitate a wide array of post-compromise activities, encompassing device code phishing, Primary Refresh Token (PRT) persistence (a mechanism to maintain access even if a user changes their password), direct email access, Business Email Compromise (BEC) operations, and SharePoint exfiltration. All these functionalities are managed through a user-friendly, React-based dashboard, simplifying complex attack workflows for operators. Michael Kelley, a Talos researcher, emphasized that these features elevate ARToken beyond a simple phishing kit, making it a "complete BEC operations environment." This means attackers can not only gain initial access but also manage and execute the entire lifecycle of a BEC fraud from a single platform, including browsing victim Microsoft 365 sessions outside the panel using a dedicated tool known as ARTBrowser.
EvilTokens itself has been at the forefront of PhaaS innovation, moving beyond mere token harvesting. It weaponizes captured tokens to exfiltrate emails, files, and other sensitive data from compromised Microsoft accounts. Furthermore, it conducts reconnaissance via the Microsoft Graph API, mapping out an organization’s digital landscape, and establishes persistent access. Critically, EvilTokens incorporates artificial intelligence (AI)-powered features to automate and scale BEC workflows. This AI capability allows the platform to sift through thousands of harvested emails, intelligently identify finance-related email threads, and even draft convincing BEC emails tailored to the victim’s context. This integration of AI represents a significant leap, enabling attackers to execute BEC fraud with unprecedented efficiency and scale.
Another notable example of a PhaaS platform adapting to this evolving threat landscape is Tycoon 2FA. Following a law enforcement operation that temporarily disrupted its activities, Tycoon 2FA has undergone a "rebound," as reported by Abnormal Security, and has subsequently adopted device code phishing as a core technique to hijack Microsoft 365 accounts. This resurgence highlights the resilience of cybercrime operations and their rapid adaptation to new attack vectors. New campaigns utilizing the rebuilt Tycoon 2FA kit feature redesigned infrastructure, multiple layers of obfuscation to evade detection, and extensive safeguards specifically designed to thwart security researchers and automated scanning tools. As eSentire noted in May 2026, Tycoon 2FA operators have repurposed their existing PhaaS kit to act as the delivery framework for OAuth device code grant phishing. The attack typically begins when a victim clicks a Trustifi click-tracking URL embedded in a lure email, culminating in the victim unknowingly granting OAuth tokens to an attacker-controlled device through Microsoft’s legitimate device-login flow at microsoft.com/devicelogin.
Profound Implications for Cybersecurity
The surge in device code phishing attacks and the proliferation of sophisticated PhaaS platforms like DEBULL, ARToken, EvilTokens, and Tycoon 2FA carry profound implications for enterprise cybersecurity. The primary danger lies in the ability of these attacks to facilitate full account takeover of Microsoft 365 environments. Once an attacker gains control, they can access a wealth of sensitive information, including emails, documents stored in OneDrive and SharePoint, and communications within Microsoft Teams.

This access can lead to severe consequences such as:
- Data Theft and Espionage: Exfiltration of confidential corporate data, intellectual property, and trade secrets.
- Financial Fraud: Direct Business Email Compromise (BEC) attacks, including invoice fraud, payroll redirection, and wire transfer scams, which can result in substantial financial losses.
- Lateral Movement: The compromised account can serve as a foothold for attackers to move laterally within the organization’s network, gaining access to other systems and resources.
- Ransomware and Disruptive Attacks: In some scenarios, account takeover can pave the way for more destructive attacks, including the deployment of ransomware or other forms of operational disruption.
- Erosion of Trust: Such attacks undermine user trust in legitimate authentication mechanisms and the security posture of their organization.
The most critical aspect of device code phishing is its effectiveness in bypassing multi-factor authentication (MFA). MFA is widely considered an essential defense against credential theft, and its circumvention by these attacks renders many traditional security measures ineffective. The use of legitimate Microsoft domains further complicates detection, as users are trained to trust these URLs, making it difficult for them to discern malicious intent.
Mitigation Strategies and Expert Recommendations
Given the evolving nature and increasing sophistication of device code phishing, organizations must adopt a multi-layered and proactive defense strategy.
-
Comprehensive User Education and Awareness Training: This remains the first line of defense. Employees must be educated about the specific tactics of device code phishing, including:
- Recognizing collaboration-themed lures and unexpected requests for authentication.
- Understanding the legitimate use of
microsoft.com/deviceloginand the importance of only entering a code when they have initiated the login process on a trusted device. - Being wary of any prompts to enter codes via email or messaging applications.
- Reporting suspicious emails or messages immediately.
-
Robust Technical Controls and Policies:

- Conditional Access Policies: Implement stringent Conditional Access policies within Microsoft Entra ID (formerly Azure Active Directory). These policies can restrict access based on user location, device compliance status, application, and real-time risk assessments, adding an extra layer of scrutiny to login attempts.
- Risk-Based MFA: Deploy adaptive or risk-based MFA, which can dynamically challenge users with stronger authentication methods when suspicious login patterns are detected.
- Disable Unnecessary Device Code Flow: For organizations or specific user groups where the OAuth 2.0 Device Authorization Grant flow is not required for legitimate business operations, consider disabling it or restricting its use to specific applications or devices.
- Enhanced Monitoring and Alerting: Implement robust security information and event management (SIEM) systems and extended detection and response (XDR) solutions to monitor for unusual sign-in attempts, abnormal token usage, and suspicious activities post-authentication. Alerts should be configured for high-risk events.
- Phishing-Resistant Authentication: Encourage and enforce the use of phishing-resistant authentication methods such as FIDO2 security keys (e.g., YubiKeys) or certificate-based authentication. These methods are inherently more resistant to device code phishing and other forms of credential theft.
- Regular Security Audits and Penetration Testing: Conduct periodic audits of Microsoft 365 configurations and user access rights. Regular penetration testing, including social engineering and phishing simulations, can help identify vulnerabilities and improve organizational resilience.
- Email Security Gateways (ESG): Implement advanced email security solutions capable of detecting and blocking sophisticated phishing lures, including those that use compromised legitimate websites for redirection.
-
Threat Intelligence Integration: Organizations should continuously integrate threat intelligence from reputable security vendors like ZeroBEC, Cisco Talos, Proofpoint, and eSentire to stay abreast of the latest phishing tactics, indicators of compromise (IoCs), and emerging PhaaS platforms.
The increasing sophistication of device code phishing, fueled by the proliferation of powerful PhaaS platforms, represents a formidable challenge to modern cybersecurity defenses. As threat actors continue to evolve their tradecraft, leveraging legitimate authentication flows and even integrating artificial intelligence into their operations, organizations must prioritize proactive defense strategies. A combination of vigilant user education, robust technical controls, and continuous threat intelligence is paramount to safeguarding Microsoft 365 environments against these insidious and highly effective attacks. The battle against identity theft remains a dynamic one, demanding constant adaptation and unwavering vigilance from all stakeholders.
