{"id":26236,"date":"2026-09-21T16:08:04","date_gmt":"2026-09-22T00:08:04","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/device-code-phishing-turning-a-convenience-feature-into-an-mfa-bypass\/"},"modified":"2026-09-21T16:08:04","modified_gmt":"2026-09-22T00:08:04","slug":"device-code-phishing-turning-a-convenience-feature-into-an-mfa-bypass","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/device-code-phishing-turning-a-convenience-feature-into-an-mfa-bypass\/","title":{"rendered":"Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass"},"content":{"rendered":"<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"2105137288\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\">\n<div class=\"article-details\" role=\"heading\">\n<span class=\"article-details__bar\" role=\"img\"><\/span><\/p>\n<p class=\"article-details__display-tag\">Phishing<\/p>\n<h1 class=\"article-details__title\">Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass <\/h1>\n<p class=\"article-details__description\">Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.<\/p>\n<p class=\"article-details__author-by\">By: Ahmed Elsayed, Ahmed Hussein, Ahmed Kamal, Mahmoud Soheem<\/p>\n<p>\t\t\t<time class=\"article-details__date\">Jul 22, 2026<\/time><br \/>\n<span>Read time:\u00a0<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words)\n\t<\/p>\n<div class=\"article-details__icons\">\n<!--Add This--><\/p>\n<div class=\"a2a_kit a2a_default_style\" data-a2a-icon-color=\"#717172\">\n<a class=\"a2a_dd addthis_link\" href=\"https:\/\/www.addtoany.com\/share\"><br \/>\n<img decoding=\"async\" alt=\"Share\" class=\"svg-icon\" src=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/share-more.svg\"\/><br \/>\n<\/a><br \/>\n<a class=\"a2a_button_print addthis_link\"><br \/>\n<img decoding=\"async\" alt=\"Print\" class=\"svg-icon\" src=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/printer.svg\"\/><br \/>\n<\/a>\n<\/div>\n<p><!--Add to Folio--><\/p>\n<div class=\"add-to-folio tooltip\">\n<span class=\"icon-folio-thin\"><\/span><\/p>\n<div class=\"right\">\n<p>Save to Folio<\/p>\n<p><i><\/i>\n<\/div>\n<\/div>\n<p><!--Subscribe--><\/p>\n<div class=\"subscribe\">\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"research-layout-divider\"\/>\n<main class=\"main--content col-xs-12 col-lg-8 col-lg-push-2\"><\/p>\n<div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><b><span class=\"body-subhead-title\">Key takeaways<\/span><\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Device code phishing involves the abuse of the OAuth 2.0 device authorization grant, a feature built for devices that cannot display a normal login page.<br \/>\n<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The victim signs in and approves on the genuine Microsoft page, so no password is stolen, and MFA is satisfied for real. The session is simply issued to the attacker instead of to the user.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">When the attacker targets the Microsoft Authentication Broker, a single approval can be turned into registered rogue devices and long-lived refresh tokens, which means durable access rather than a one-off login.<br \/>\n<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The best defenses are heightening user awareness, blocking the device-code flow where it is not needed, and using a detection solution that catches the behavior and keeps watch on the underlying events.<\/span><\/li>\n<\/ul>\n<p><b><span class=\"body-subhead-title\">Introduction\u00a0<\/span><\/b><\/p>\n<p>For years, the advice to users was simple: turn on multi-factor authentication (MFA), and most account takeovers can be prevented. That advice still holds, and MFA still blocks most <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/from-stealers-to-systems-the-new-model-of-credential-theft\">password-based attacks<\/a>. The problem is that attackers adapt, and the more an organization relies on a single control, the more attention that control attracts.<\/p>\n<p>The first big shift was adversary-in-the-middle <a href=\"https:\/\/www.trendmicro.com\/en_us\/what-is\/phishing.html\">phishing<\/a>, where a proxy site sits between the user and Microsoft and relays the login in real time to capture the session cookie. Device code <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/threat-landscape\/email-threat-landscape-report-evolving-threats-in-email-based-attacks\">phishing<\/a> is the next step, and in some ways, it is cleaner for the attacker. There is no fake login site to build or to get blocked, and there is nothing visually wrong for the user to notice, because the page they enter their password on really is Microsoft. The only unusual thing is a short code and a plausible reason to enter it.\u00a0<\/p>\n<p><b><span class=\"body-subhead-title\">How device code authentication is meant to work<\/span><\/b><\/p>\n<p>The device authorization grant exists for a sensible reason. Some devices cannot show a normal sign-in page or do not have a keyboard: smart TVs and conference-room systems are common examples. Instead of typing a password on the device, you are given a short code and asked to finish signing in on a second screen.\u00a0<\/p>\n<p>In a normal flow, the device asks Microsoft for a code, shows it to you, and you open microsoft.com on your phone or laptop, type the code, and approve. Microsoft then issues the tokens back to the device that requested the code. The important detail is that the device asking for access and the person approving it are the same party, sitting in the same room.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<img decoding=\"async\" alt=\"Figure 1. Device-code flow as designed. The device that requests the code is the device that receives the tokens. \" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-1.jpg\"\/><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 1. Device-code flow as designed. The device that requests the code is the device that receives the tokens. <\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-1.jpg\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div>\n<div class=\"richText\">\n<div>\n<p><b><span class=\"body-subhead-title\">How attackers abuse it<\/span><\/b><\/p>\n<p>The attack works by breaking that assumption. The attacker plays the role of the input-limited device. They start a genuine device-code request, receive a real Microsoft code, and then trick a victim into approving it. The victim signs in, and the attacker collects the result.<\/p>\n<ol>\n<li>The attacker\u2019s server starts a device-code sign-in with Microsoft and receives a valid, short-lived code.<\/li>\n<li>A lure delivers that code to the victim with a believable reason to use it, usually to view a shared document or to verify their account.<\/li>\n<li>The victim opens the real Microsoft sign-in page, enters the code, signs in, and completes MFA.<\/li>\n<li>Because the victim approved the attacker\u2019s pending request, Microsoft issues the tokens to the attacker\u2019s server after the MFA requirement has been satisfied.<\/li>\n<li>The attacker uses those tokens from their own systems, often registering devices, logging on to Microsoft 365 Outlook, and creating mailbox rules so the access survives and stays unnoticed.<\/li>\n<\/ol>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<img decoding=\"async\" alt=\"Figure 2. The same flow, abused. The attacker requests the code and receives the tokens, while the victim performs the sign-in. \" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-2.jpg\"\/><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 2. The same flow, abused. The attacker requests the code and receives the tokens, while the victim performs the sign-in. <\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-2.jpg\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><b><span class=\"body-subhead-title\">Microsoft 365 account takeover case\u00a0<\/span><\/b><\/p>\n<p>A recent case shows how polished this has become. The intrusion started not with a single email but with a conversation. The attacker, posing as a partner from a law firm, opened with a friendly note about a possible collaboration and exchanged several messages before ever sending a link. By the time the link arrived, it felt like part of a normal thread.\u00a0<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a data-modal-title=\"Figure 3. Initial email sent to victim\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-3.jpg\" id=\"fa143b\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 3. Initial email sent to victim\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-3.jpg\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 3. Initial email sent to victim<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-3.jpg\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>The link itself was built to survive inspection. The text on screen showed a familiar-looking corporate address, but the real destination was a page hosted on Google Sites, a trusted service that carries a good reputation and is rarely blocked. From there, the victim was bounced through an open redirect on a compromised, legitimate website, with a harmless decoy address in plain sight and the real target tucked into a parameter. The final page sat behind a fake human-check prompt to keep automated scanners away.\u00a0<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<img decoding=\"async\" alt=\"Figure 4. The delivery chain we observed. Each hop uses a trusted or throwaway service to stay ahead of email and URL filtering. \" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-4.jpg\"\/><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 4. The delivery chain we observed. Each hop uses a trusted or throwaway service to stay ahead of email and URL filtering. <\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-4.jpg\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>The landing page looked like a document-sharing portal. It displayed a verification code and walked the user through entering it at the Microsoft sign-in.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a data-modal-title=\"Figure 5. The lure: a familiar shared-document page on a trusted domain. Nothing downloads, and no warning appears.\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-5.jpg\" id=\"66aca9\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 5. The lure: a familiar shared-document page on a trusted domain. Nothing downloads, and no warning appears.\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-5.jpg\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 5. The lure: a familiar shared-document page on a trusted domain. Nothing downloads, and no warning appears.<\/figcaption><\/div>\n<\/figure>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a data-modal-title=\"Figure 6. The hand-off. The page shows a verification code and tells the user to enter it at the real Microsoft sign-in. \" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-6.jpg\" id=\"dd9599\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 6. The hand-off. The page shows a verification code and tells the user to enter it at the real Microsoft sign-in. \" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-6.jpg\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 6. The hand-off. The page shows a verification code and tells the user to enter it at the real Microsoft sign-in. <\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/device-code-phishing\/Fig-6.jpg\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>In one of the cases we have investigated, a few hours after the user approved the request, the attacker signed in from abroad, registered a series of devices under the account, created a hidden inbox rule to bury replies and bounce messages, and used the mailbox to send the next wave of phishing to hundreds of external recipients. The endpoint itself was never touched. Everything happened in the cloud, off the victim\u2019s machine, which is part of why this style of attack is hard to detect with endpoint tooling alone.<\/p>\n<p><b><span class=\"body-subhead-title\">How to detect device code phishing<\/span><\/b><\/p>\n<p>Because the attack occurs in the identity layer, that is where the relevant signals can be detected. Useful things to watch for:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Device-code sign-ins:<\/b> any sign-in that used the device-code authentication protocol, which should be rare and explainable in most environments.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Authentication Broker activity:<\/b> sign-ins to the Microsoft Authentication Broker from an unfamiliar country, network, or unmanaged device.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Device registration spikes:<\/b> new device registrations, especially several in a short window or from unfamiliar IP addresses.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Mailbox rule changes:<\/b> new inbox rules that move mail to obscure folders, mark it read, or delete it, which is the classic clean-up step after takeover.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Impossible or atypical travel:<\/b> successful sign-ins from outside the regions a user normally works in, correlated with the events above.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>How to defend against attacks<\/b><\/span><\/li>\n<\/ul>\n<p>No single setting solves this. Treat it as a layered defense, starting with people and reinforced by policy.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Awareness first.<\/b> Teach users that an unexpected request to enter or read out a code is a red flag and give them an easy way to report it. An alert user stops the attack before any technical control is tested.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Block the device-code flow.<\/b> Disable the <a href=\"https:\/\/learn.microsoft.com\/entra\/identity-platform\/v2-oauth2-device-code\">OAuth device-code authentication flow<\/a> with a <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/conditional-access\/concept-authentication-flows\">Conditional Access<\/a> policy wherever it is not genuinely required. Most organizations can <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/conditional-access\/policy-block-authentication-flows\">block it<\/a> broadly and allow narrow exceptions.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Restrict and monitor devices.<\/b> Limit who can register devices, require managed and compliant devices for access to mail and data, and lower the per-user device limit so a fleet of rogue devices cannot accumulate unnoticed.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Tighten identity controls.<\/b> Enforce named-location policies, enable Continuous Access Evaluation and token protection, and revoke sessions automatically when risk rises.<\/span><\/li>\n<\/ul>\n<p><b><span class=\"body-subhead-title\">Conclusion<\/span><\/b><\/p>\n<p>Device code phishing is a reminder that attackers go after the seams between features, not just the features themselves. Nothing here is a software flaw. It is a legitimate flow, a trusted login page, and a believable story, combined into an attack that quietly sidesteps the one control most organizations lean on. The good news is that it is also very preventable. Blocking the flow where it is not needed, moving to phishing-resistant MFA, and teaching people to distrust unexpected codes will take most of the risk off the table.<\/p>\n<p><span class=\"body-subhead-title\"><b>Detection with\u00a0TrendAI Vision One\u2122<\/b><\/span><\/p>\n<p>At the web layer, the phishing URLs used in this attack are detected by \u00a0TrendAI Vision One\u2122 Web Reputation Services as dangerous URLs, with the credential-harvesting page flagged under the detection name HTML.Phish.Microsoft. Blocking these URLs stops the victim from ever reaching the code prompt, which is why web reputation and URL filtering are a useful backstop behind user awareness.<\/p>\n<p><b><span class=\"body-subhead-title\">TrendAI Vision One\u2122 Threat Intelligence Hub<\/span><\/b><\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/threat-intelligence.html\">TrendAI Vision One\u2122 Threat Intelligence Hub <\/a>provides the latest insights on emerging threats and threat actors, exclusive strategic reports from TrendAI\u2122 Research, and TrendAI Vision One\u2122 Threat Intelligence Feed in the TrendAI Vision One\u2122 platform.<\/p>\n<p><b>Emerging Threats:<\/b>\u00a0<a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence_insights?name=Device%20Code%20Phishing%20Bypasses%20MFA%20Protections\">Device Code Phishing Bypasses MFA Protections<\/a><\/p>\n<h2><span class=\"body-subhead-title\"><span class=\"rte-sub-menu-text\">TrendAI Vision One\u2122 Intelligence Reports (IOC Sweeping)\u00a0<\/span><\/span><\/h2>\n<ul>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence?intrusionSet=Device%20Code%20Phishing%20Bypasses%20MFA%20Protections\">Device Code Phishing Bypasses MFA Protections<\/a><\/span><\/li>\n<li>\u00a0<\/li>\n<\/ul>\n<p><b><span class=\"body-subhead-title\">TrendAI Vision One\u2122 XDR Data Explorer App\u00a0<\/span><\/b><\/p>\n<p>TrendAI Vision One\u2122 customers can use the XDR Data Explorer App to match or hunt the malicious indicators mentioned in this blog post with data in their environment.\u00a0\u00a0\u00a0\u00a0<\/p>\n<p>Where Microsoft Entra ID is integrated with \u00a0TrendAI Vision One\u2122, the following \u00a0XDR Data Explorer App queries surface the two events that matter most in this attack. The first returns any successful device-code authorization, which should be rare and explainable in most environments:<\/p>\n<p><span class=\"blockquote\">pname: &#8220;Microsoft Entra ID&#8221; AND authenticationProtocol: deviceCode AND eventName: IDENTITY_IAM_SIGN_INS AND status: 0<\/span><\/p>\n<p>The second returns newly registered devices, which is how the attacker turns a single approval into lasting access:<\/p>\n<p><span class=\"blockquote\">pname: &#8220;Microsoft Entra ID&#8221; AND eventName: IDENTITY_AAD_DIR_AUDIT AND eventCategory: Device AND actionName: Add device AND initiatedByAppDisplayName: Device Registration Service AND result: success<\/span><\/p>\n<p>Although the above filter would detect device registration events, it is expected to have a high rate of legitimate activities. The authentication event on the Device Registration Service resource could be tracked to identify sessions with the original transfer method as device-code flow, which could alert about a device-code token being used to log in to the device registration service. Detection logic as below:\u00a0<\/p>\n<p><span class=\"blockquote\">pname: &#8220;Microsoft Entra ID&#8221; AND eventName: IDENTITY_IAM_SIGN_INS AND status: 0 AND rawDataStr: &#8220;\\&#8221;OriginalTransferMethod&#8221;:&#8221;deviceCodeFlow&#8221;&#8221; AND targetResourceDisplayName: &#8220;Device Registration Service&#8221;<\/span><\/p>\n<p>These same behaviors are also surfaced natively in TrendAI Vision One\u2122 through Observed Attack Techniques and Workbench detection rules:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Potential Device Code Token Generation<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Device Registration Resource Access via Device Code Token\u00a0<\/b><\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div class=\"responsive-table-wrap\">\n<p><b>MITRE ATT&amp;CK techniques<\/b><\/p>\n<table style=\"width: 100.0%;font-family: Arial , sans-serif;font-size: 12.0px;\">\n<thead>\n<tr style=\"border-bottom: 2.0px solid rgb(208,208,208);\">\n<th style=\"padding: 10.0px 14.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;width: 220.0px;\">Tactic<\/th>\n<th style=\"padding: 10.0px 32.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;\">Technique<\/th>\n<th style=\"padding: 10.0px 32.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;\">ID<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(238,237,254);color: rgb(60,52,137);\">Resource Development<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Acquire<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">\/Compromise<\/code> Infrastructure (redirectors, hosting)<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1583<\/code><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">\/<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1584<\/code><\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(250,238,218);color: rgb(99,56,6);\">Initial Access<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Phishing: Spearphishing Link<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1566.002<\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(250,236,231);color: rgb(113,43,19);\">Credential Access<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Multi-Factor Authentication Request Generation (device code)<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1621<\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(251,234,240);color: rgb(114,36,62);\">Credential Access<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Steal Application Access Token<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1528<\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(234,243,222);color: rgb(39,80,10);\">Defense Evasion\/Lateral Movement<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Use Alternate Authentication Material: Application Access Token<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1550.001<\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(230,241,251);color: rgb(12,68,124);\">Persistence<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Account Manipulation: Device Registration<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1098.005<\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(250,236,231);color: rgb(113,43,19);\">Persistence<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Account Manipulation<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">\/Modify<\/code> Authentication Process: Multi-Factor Authentication (additional MFA<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">\/security<\/code> info)<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1098<\/code><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">\/<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1556.006<\/code><\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(250,238,218);color: rgb(99,56,6);\">Collection<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Email Collection; Email Hiding Rules<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1114<\/code><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">\/<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1564.008<\/code><\/code><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(238,237,254);color: rgb(60,52,137);\">Defense Evasion<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Impersonation<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">T1656<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><b><span class=\"body-subhead-title\">Indicators of compromise (IOCs)<\/span><\/b><\/p>\n<p><i>Representative indicators from the activity described above. They are shown defanged. Some are shared or legitimate services that the attacker abused, so validate before blocking.<\/i>\u00a0<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div class=\"responsive-table-wrap\">\n<table style=\"width: 100.0%;font-family: Arial , sans-serif;font-size: 12.0px;\">\n<thead>\n<tr style=\"border-bottom: 2.0px solid rgb(208,208,208);\">\n<th style=\"padding: 10.0px 14.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;width: 220.0px;\">Type<\/th>\n<th style=\"padding: 10.0px 32.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;\">Indicator<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(238,237,254);color: rgb(60,52,137);\">Sender\/impersonation domains<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">rlcounsel[.]com<\/code> , <code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">cholaw-kr[.]co<\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(250,238,218);color: rgb(99,56,6);\">Lure pages (trusted host)<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">sites.<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">google[.]com<code>&lt;&gt; style=\"font-family:monospace;font-size:12px;background:#f4f4f4;padding:1px 5px;border-radius:3px;\"&gt;\/view\/businessprofileoverview<\/code><\/code> ; <code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">\/corporateprofiledetails<\/code> ; <code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">\/profileportfoliodetailsdata<\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(250,236,231);color: rgb(113,43,19);\">Open redirectors (compromised)<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">eusei[.]com<code>&lt;&gt; style=\"font-family:monospace;font-size:12px;background:#f4f4f4;padding:1px 5px;border-radius:3px;\"&gt;\/dir\/redirects.php<\/code><\/code> ; <code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">cineuropa[.]org<code>&lt;&gt; style=\"font-family:monospace;font-size:12px;background:#f4f4f4;padding:1px 5px;border-radius:3px;\"&gt;\/nll.aspx<\/code><\/code> ; <code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">zrdesignlabo[.]com<code>&lt;&gt; style=\"font-family:monospace;font-size:12px;background:#f4f4f4;padding:1px 5px;border-radius:3px;\"&gt;\/st-manager\/click\/track<\/code><\/code><\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(251,234,240);color: rgb(114,36,62);\">Phishing endpoints<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\"><code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">up88qope1z[.]hlpadditives[.]com<\/code> ; <code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">zr6dgshpvf[.]flosli[.]com<\/code> ; <code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">profileupdate-collaboration[.]stefan-dufva[.]workers[.]dev<\/code><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(234,243,222);color: rgb(39,80,10);\">Attacker IP addresses<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">104.219.<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">238[.]253<\/code> ; 43.165.<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">1[.]42<\/code> ; 40.124.<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">130[.]50<\/code> ; 18.118.<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">111[.]82<\/code> ; 83.136.<code style=\"font-family: monospace;font-size: 12.0px;background: rgb(244,244,244);padding: 1.0px 5.0px;\">210[.]246<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><i>This note is shared to help defenders recognize and stop an active technique. Validate all indicators in your own environment before acting.<\/i><\/p>\n<\/div>\n<\/div>\n<\/div>\n<section class=\"tag--list\">\n<div class=\"tag--list-title\">Tags<\/div>\n<div class=\"tag--list-tags\">\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:threats\/phishing\">Phishing<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:medium\/article\">Articles, News, Reports<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:article-type\/research\">Research<\/a>\n<\/div>\n<\/section>\n<p><\/main><br \/>\n<sidebar class=\"sidebar--left col-xs-12 col-lg-2 col-lg-pull-8\"><\/p>\n<h3 class=\"article-authors__title\">\n<p>\t\tAuthors<\/p>\n<\/h3>\n<p><!-- \/* Show Trend Micro if we don't have any authors for this article *\/ --><\/p>\n<ul class=\"article-authors__list\">\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Ahmed Elsayed<\/p>\n<p class=\"article-authors__list-items__position\">Incident Response Analyst<\/p>\n<\/div>\n<\/li>\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Ahmed Hussein<\/p>\n<p class=\"article-authors__list-items__position\">Manager &#8211; Threat IR &amp; Forensic<\/p>\n<\/div>\n<\/li>\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Ahmed Kamal<\/p>\n<p class=\"article-authors__list-items__position\">Sr. Incident Response Analyst<\/p>\n<\/div>\n<\/li>\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Mahmoud Soheem<\/p>\n<p class=\"article-authors__list-items__position\">Sr. Incident Response Analyst<\/p>\n<\/div>\n<\/li>\n<\/ul>\n<div class=\"article-authors__btn-wrapper\" role=\"button\">\n<a class=\"article-authors__button\" href=\"mailto:tm_research@trendmicro.com\" id=\"article-authors-contact-us-button\" target=\"target\"><br \/>\n\t\tContact Us<br \/>\n\t<\/a>\n<\/div>\n<p><\/sidebar><br \/>\n<sidebar class=\"sidebar--right col-xs-12 col-lg-2\"><\/p>\n<div class=\"sidebar--wrapper\" role=\"contentinfo sidebar\">\n<div class=\"row-1\" role=\"contentinfo related articles\">\n<div class=\"related--articles\" role=\"contentinfo related articles\">\n<h3 class=\"related--articles-title\">Related Articles<\/h3>\n<ul class=\"related--articles-items\">\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/24\/c\/unveiling-earth-kapre-aka-redcurls-cyberespionage-tactics-with-t.html\"><br \/>\n\t\t\t\t\tUnveiling Earth Kapre aka RedCurl\u2019s Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/22\/h\/secure-access-service-edge-sase-security-company.html\"><br \/>\n\t\t\t\t\tA Secure Access Service Edge (SASE) Guide for Leaders<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/26\/g\/open-secure-ai-alliance.html\"><br \/>\n\t\t\t\t\tWhy the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<\/ul>\n<\/div>\n<div class=\"archived--link\">\n<div class=\"archived--link-text\">\n<a href=\"\/en_us\/research.html\"><br \/>\n\t\t\t\tSee all articles<br \/>\n\t\t\t<\/a>\n<\/div>\n<div class=\"archived--link-icon\">\n<a href=\"\/en_us\/research.html\"><br \/>\n<span class=\"icon-chevron-right\"><\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/sidebar><br \/>\n<\/article>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>PhishingDevice Code Phishing: Turning a Convenience Feature Into an MFA BypassDevice code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.By: Ahmed Elsayed, Ahmed Hussein, Ahmed Kamal, Mahmoud SoheemJul 22, 2026Read time:(words)Save to FolioKey takeawaysDevice code phishing involves the <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32777],"tags":[],"class_list":["post-26236","post","type-post","status-publish","format-standard","hentry","category-trend-micro"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26236","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26236"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26236\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26236"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}