hacker-news · Crawled Jul 7, 2026

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

1 IoCs
Read original article ↗

AI Summary

A phishing campaign leveraging Microsoft's device-code flow has been observed targeting Microsoft 365 accounts using collaboration-themed lures. The attack abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass MFA, tricking users into authorizing an attacker-controlled session. The campaign, linked to reusable tooling called DEBULL, shares tactics with Storm-2372 and is part of a growing trend in phishing-as-a-service (PhaaS) platforms like EvilTokens and ARToken that enable account takeover and business email compromise.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain microsoft[.]com/devicelogin Details →