Trusted Design

GhostCode: Dissecting a Novel Device Code Phishing Kit

概要

In late August 2026, a sophisticated device code phishing campaign was identified, distributed through web contact forms. Threat actors impersonated procurement officers from legitimate businesses, specifically BJ's Wholesale Club, using lookalike domains registered with Zoho Mail. The campaign, tracked as GhostCode, abused Microsoft's OAuth 2.0 device authorization grant flow to obtain authentication tokens. Victims received WeTransfer links to password-protected HTML files containing three layers of obfuscation: junk padding, character-level HTML comment injection, and AES-256-GCM encrypted redirect URLs. After passing multiple security checks including Cloudflare Turnstile, victims were directed to legitimate Microsoft sign-in pages where they unwittingly authorized attacker-controlled devices. Within 78 seconds of successful authentication, threat actors registered three devices, obtained Primary Refresh Tokens, and harvested emails using residential proxy rotation to evade detection.

Created: 2026-09-16

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る