New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA

Medium · Hackread ·

What happened

eSentire uncovered GhostCode, a phishing kit that abuses Microsoft OAuth to steal tokens and register attacker devices, letting attackers access Microsoft 365 accounts even with MFA enabled.

What to do now

Revoke suspicious sessions/refresh tokens, audit new device registrations and OAuth consents, enforce Conditional Access with compliant devices, block legacy auth, enable phishing-resistant MFA, train users.

Original source

Hackread

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news