Phishing Using Microsoft's Device Code Flow

A new phishing campaign is exploiting Microsoft's Device Code Flow authentication feature to steal account access tokens without ever using a fake website. Attackers trick victims into opening a malicious document that directs them to copy a one time code and past it into the real Microsoft login page, where they unknowingly authorize a malicious device. Once the code is approved, attackers receive access tokens that allow them to read emails, access files and monitor Team chats. This threat is dangerous because it bypasses security training by making the attack appear completely safe and authentic.