惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
B
Blog
月光博客
月光博客
博客园 - 【当耐特】
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
博客园 - Franky
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
B
Blog RSS Feed
H
Help Net Security

Human Risk Management Blog

Future-Proofing Organizations in the Face of AI What Security Can Learn From Dinosaurs Inside the OS-Aware Phishing Kit Profiling Your Device CyberheistNews Vol 16 #30 [Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks Majority of Organizations Hit by Targeted Impersonation Attacks The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response
Report: Device Code Phishing is Surging
KnowBe4 Team · 2026-06-26 · via Human Risk Management Blog

Multiple sophisticated phishing kits are now focusing on harvesting device codes to breach accounts without a password, according to researchers at LevelBlue.

Device code phishing exploits a legitimate Microsoft authentication flow to harvest Microsoft 365 access and refresh tokens without ever capturing a password,” the researchers explain. “The core mechanic is straightforward: whoever initiates the authentication request receives the resulting tokens. Once obtained, the tokens allow attackers to access Microsoft 365 services, maintain persistent access through refresh tokens, and conduct follow-on activities such as further reconnaissance, phishing, and data extraction.”

Top commodity phishing platforms, including Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r, have incorporated this ability, allowing unskilled threat actors to launch device code phishing attacks.

“Tycoon2FA provides the clearest example of how phishing kits mature over time,” the researchers write. “What began in 2023 as a straightforward AiTM credential harvester evolved into one of the most sophisticated PhaaS platforms documented. Despite a coordinated Europol and Microsoft takedown in March 2026, Tycoon2FA resumed operations within weeks, now with device code flow capability layered on top of its existing AiTM infrastructure. EvilTokens and Kali365 follow a similar trajectory, launching in early 2026 with AI-augmented capabilities already integrated and continuing to improve their functionality since launch. Kits that survive their first year tend to become significantly more dangerous in their second.”

The researchers expect commodity phishing kits to continue incorporating new techniques in order to overcome defenses.

“Device code flow phishing is accelerating rapidly and shows no signs of slowing,” LevelBlue concludes. “What began as a relatively simple lure has evolved into a sophisticated process that is now easily accessible to threat actors. The affiliate programs offered by PaaS platforms further lower the barrier, enabling both experienced operators and less-skilled actors to launch targeted and opportunistic campaigns against organizations.”

LevelBlue has the story: The Device Code Phishing Tsunami: What We’re Seeing in the Wild