In late August 2026, a sophisticated device code phishing campaign was identified, distributed through web contact forms. Threat actors impersonated procurement officers from legitimate businesses, specifically BJ's Wholesale Club, using lookalike domains registered with Zoho Mail. The campaign, tracked as GhostCode, abused Microsoft's OAuth 2.0 device authorization grant flow to obtain authentication tokens. Victims received WeTransfer links to password-protected HTML files containing three layers of obfuscation: junk padding, character-level HTML comment injection, and AES-256-GCM encrypted redirect URLs. After passing multiple security checks including Cloudflare Turnstile, victims were directed to legitimate Microsoft sign-in pages where they unwittingly authorized attacker-controlled devices. Within 78 seconds of successful authentication, threat actors registered three devices, obtained Primary Refresh Tokens, and harvested emails using residential proxy rotation to evade detection.
Created: 2026-09-16
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。