GhostCode Phishing Kit Targets Microsoft 365 Tokens and Device Registration

Moyen · Hackread ·

En bref

  • eSentire uncovered a phishing kit called GhostCode that targets Microsoft 365 accounts.
  • The kit abuses Microsoft OAuth to steal access tokens and register attacker devices.
  • Stolen tokens can allow account access without needing the original password.
  • No CVE is associated, so patching alone will not address the risk.
  • K-12 and government Microsoft 365 tenants should review identity controls and monitoring.

eSentire has detailed a phishing kit called GhostCode that targets Microsoft 365 accounts. Instead of only capturing passwords, the kit reportedly abuses Microsoft's OAuth authorization flow to obtain access tokens. Those tokens can let an attacker act as the signed-in user without needing the password again.

The kit also reportedly registers attacker-controlled devices. That matters because device registration can create persistent access and may satisfy some access policies. With stolen tokens and a registered device, an intruder can reach Microsoft 365 services such as email, files, and collaboration tools. MFA alone may not stop this if the token has already been issued.

For K-12 and government organizations, the risk is concentrated in Microsoft 365 tenants. Staff and student accounts are attractive for data access, business email compromise, and lateral movement. A single compromised account can expose sensitive student records, internal communications, or financial systems connected to the tenant.

This is not a software vulnerability with a CVE. It is an abuse of legitimate identity features. That makes patching insufficient. Defenders need to focus on identity configuration, monitoring, and user reporting. The absence of a CVE does not reduce the need to treat token theft and rogue device registration as serious.

What to watch: unusual OAuth consent grants, new device registrations, impossible-travel or anomalous token use, and mailbox rule changes. Verify vendor reporting and check tenant logs. If suspicious activity is found, revoke refresh tokens, remove unauthorized devices, and review conditional access policies.

À faire maintenant

  1. Review and restrict who can register devices in Entra ID; require admin approval or block registration for non-managed devices.
  2. Audit OAuth apps and enterprise applications, remove unused or unknown grants, and restrict user consent to trusted publishers.
  3. Enforce phishing-resistant MFA such as FIDO2, Windows Hello, or certificate-based authentication, especially for administrators.
  4. Monitor sign-in and audit logs for token issuance, new device registrations, unusual IP addresses, and suspicious mailbox rules.
  5. Enable token protection and continuous access evaluation where available, and shorten token lifetimes for high-risk accounts.
  6. Train users to report unexpected Microsoft login prompts and OAuth consent screens instead of approving them.
  7. Prepare an incident response playbook to revoke sessions and tokens, reset credentials, remove devices, and notify privacy or legal teams if student data is exposed.

Source originale

Hackread

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber