Drooid Logo
Back to story perspectives

Full Breakdown

Surge in OAuth Device Code Phishing Attacks Targeting Microsoft 365 Accounts

12/20/2025, 5:42:11 AM

Overview of the Phishing Campaigns

A significant increase in phishing campaigns exploiting Microsoft’s OAuth 2.0 device authorization flow has been reported, with various threat actors, including state-aligned and financially motivated groups, targeting Microsoft 365 accounts. According to a recent advisory from Proofpoint, these campaigns utilize social engineering tactics to deceive users into approving malicious applications, leading to unauthorized access, data theft, and account compromise.

Mechanism of the Attacks

The phishing attacks leverage the OAuth 2.0 device authorization grant, a legitimate process intended for users to sign in on devices with limited input capabilities. Attackers generate a device code through a malicious application and prompt victims to enter this code on Microsoft’s trusted verification page. Once the victim submits the code, the attacker receives a valid access token, granting them control over the compromised account.

Techniques Employed

Proofpoint observed a marked rise in the use of device code phishing techniques, particularly by September 2025. Attackers have employed various methods, including QR codes, embedded buttons, and hyperlinked text, to initiate their attacks. Common lures include claims of document sharing, token reauthorization, or security verification. For instance, one campaign detected on December 8 involved a fraudulent document titled “Salary Bonus + Employer Benefit Reports 25,” which directed victims to enter a device code on a spoofed Microsoft login page.

Threat Actor Profiles

Among the identified threat actors, a financially motivated group known as TA2723 began utilizing device code phishing in October 2025, targeting victims with spoofed salary documents. Additionally, a Russia-aligned group named UNK_AcademicFlare has targeted government, academic, and transportation sectors in the US and Europe, employing compromised email accounts and spoofed OneDrive links to facilitate their phishing workflows.

Recommendations for Organizations

In light of the growing prevalence of these phishing campaigns, Proofpoint advises organizations to enhance their OAuth controls and educate users on the risks of entering device codes from untrusted sources. The advisory emphasizes that the misuse of OAuth authentication flows is likely to continue escalating, particularly with the increasing adoption of passwordless authentication methods.

Official Statements & Responses

Proofpoint has highlighted the rapid adaptation of threat actors in exploiting legitimate authentication features for malicious purposes. The company asserts that organizations must take proactive measures to safeguard against these evolving threats.

Conflicting Reports & Gaps

While the advisory from Proofpoint outlines the surge in device code phishing attacks, there is limited information regarding the specific number of incidents or the extent of data compromised in these campaigns. Further data on the effectiveness of current security measures against these phishing techniques is also lacking.

Verbatim Quotes

“Proofpoint assesses that the abuse of OAuth authentication flows will continue to grow with the adoption of FIDO compliant MFA controls.” — Proofpoint, Cybersecurity Research Firm

This article synthesizes the findings from multiple sources to provide a comprehensive overview of the recent surge in OAuth device code phishing attacks targeting Microsoft 365 accounts.