New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA
Medium · Hackread ·
What happened
eSentire uncovered GhostCode, a phishing kit that abuses Microsoft OAuth to steal tokens and register attacker devices, letting attackers access Microsoft 365 accounts even with MFA enabled.
What to do now
Revoke suspicious sessions/refresh tokens, audit new device registrations and OAuth consents, enforce Conditional Access with compliant devices, block legacy auth, enable phishing-resistant MFA, train users.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.