What is device code phishing, and why are Russian spies so successful at it?

Date:

Share:



Researchers have uncovered a sustained and ongoing campaign by Russian spies that uses a clever phishing technique to hijack Microsoft 365 accounts belonging to a wide range of targets, researchers warned.

The technique is known as device code phishing. It exploits “device code flow,” a form of authentication formalized in the industry-wide OAuth standard. Authentication through device code flow is designed for logging printers, smart TVs, and similar devices into accounts. These devices typically don’t support browsers, making it difficult to sign in using more standard forms of authentication, such as entering user names, passwords, and two-factor mechanisms.

Rather than authenticating the user directly, the input-constrained device displays an alphabetic or alphanumeric device code along with a link associated with the user account. The user opens the link on a computer or other device that’s easier to sign in with and enters the code. The remote server then sends a token to the input-constrained device that logs it into the account.

Device authorization relies on two paths: one from an app or code running on the input-constrained device seeking permission to log in and the other from the browser of the device the user normally uses for signing in.

A concerted effort

Advisories from both security firm Volexity and Microsoft are warning that threat actors working on behalf of the Russian government have been abusing this flow since at least last August to take over Microsoft 365 accounts. The threat actors masquerade as trusted, high-ranking officials and initiate conversations with a targeted user on a messenger app such as Signal, WhatsApp, and Microsoft Teams. Organizations impersonated include:



Source link

━ more like this

Gulf economies are facing the worst regional economic shock since 1990 – London Business News | Londonlovesbusiness.com

The ongoing conflict involving the United States, Israel, and Iran has led to severe economic repercussions across the Gulf region, significantly impacting key...

A PlayStation Portal update is adding a 1080p High Quality mode

Sony is rolling out a firmware update for its PlayStation Portal handheld that introduces a new quality option for both Remote Play and...

Iran warns the Strait of Hormuz ‘cannot be as it was before’ as oil tops $100 – London Business News | Londonlovesbusiness.com

Brent crude surged above $100 a barrel on Tuesday, hitting $102.69, while US West Texas Intermediate rose to $95.92, amid escalating tensions over...

Samsung is reportedly doubling down on cost cuts and it’s bad news for Galaxy fans

Samsung’s mobile business is reportedly under pressure, and that could spell bad news for Galaxy fans. According to a report from FNN News,...

How Kie.ai’s GPT-5.4 API boosts task automation and decision-making for businesses – London Business News | Londonlovesbusiness.com

Businesses are increasingly faced with the challenge of managing vast amounts of data, automating repetitive tasks, and making quick, yet well-informed decisions. The...
spot_img