Microsoft 365 Phishing Alert: How Attackers Bypass MFA with Evilginx & Device Code Flow (2026)

In the ever-evolving landscape of cybersecurity, the revelation of misconfigured servers and their role in facilitating phishing operations is a stark reminder of the vulnerabilities that persist in our digital infrastructure. This article delves into the intricate details of a recent discovery, where a seemingly innocuous misstep has exposed a sophisticated phishing campaign targeting Microsoft 365 users. Through a meticulous analysis, we unravel the layers of this attack, shedding light on the techniques employed and the implications for both defenders and the broader cybersecurity community.

The Unseen Threat

What makes this incident particularly intriguing is the subtle nature of the initial breach. A simple command, python3 -m http.server 8080, left a backdoor open, revealing a trove of sensitive information. The French security firm Lexfo, in their pursuit of uncovering the operator's toolkit, stumbled upon a treasure trove of data, including phishing configurations, credential-harvesting logs, and even Telegram session files. This discovery not only highlights the importance of server configuration but also underscores the potential for hidden threats within seemingly mundane settings.

The Phishing Operators

The three phishing operators, collectively known as codemado, were operating from a public GitHub repository. Their toolkit, a custom fork of the open-source Evilginx proxy, was a testament to the power of collaboration and the ease of access to advanced hacking tools. The largest of these operators had been running for over a year, targeting corporate mailboxes with a precision that suggests a well-oiled machine.

One of the most striking aspects of this operation is the use of device code phishing, a technique that leverages Microsoft's own OAuth device code flow. By generating a real device code and presenting it in an Authenticator-themed lure page, the attacker tricks the victim into clearing MFA on genuine Microsoft infrastructure. This method, documented by Microsoft itself, showcases the sophistication and adaptability of modern phishing campaigns.

The Role of AI

The involvement of AI in the development of these phishing tools adds a layer of complexity. While the core frameworks were not built from scratch, the glue code around them, the scripts and phishlets, bore the unmistakable marks of AI assistance. This raises questions about the accessibility of advanced hacking tools and the potential for widespread adoption of AI-driven phishing campaigns.

The Defender's Dilemma

For defenders, the challenge lies in addressing these emerging threats. While phishing-resistant MFA, FIDO2, and passkeys can mitigate the impact of Evilginx-based attacks, device code abuse presents a unique challenge. The solution, as highlighted by Microsoft, lies in Conditional Access policies that can block device code flow and reevaluate stolen tokens from outside allowed ranges.

The Broader Implications

This incident serves as a reminder of the interconnected nature of the cybersecurity ecosystem. The three operators, connected through a shared GitHub repository and Telegram channel, were part of a larger network of phishing-as-a-service providers. The discovery of The Quarry, a phishing-as-a-service ecosystem, underscores the need for a holistic approach to cybersecurity, where threats are addressed at their source.

The Way Forward

As the cybersecurity landscape continues to evolve, the battle against phishing campaigns demands a multi-faceted approach. Defenders must stay vigilant, adapt to emerging threats, and collaborate across the industry to address the root causes of such incidents. The discovery of these misconfigured servers and the subsequent phishing operations serves as a call to action, urging us to fortify our defenses and protect our digital assets.

In conclusion, this incident is a stark reminder of the vulnerabilities that lurk in the shadows of our digital infrastructure. As we navigate the complexities of modern cybersecurity, it is imperative that we remain vigilant, adaptable, and collaborative in our efforts to safeguard our digital world.

Microsoft 365 Phishing Alert: How Attackers Bypass MFA with Evilginx & Device Code Flow (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Manual Maggio

Last Updated:

Views: 5638

Rating: 4.9 / 5 (49 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Manual Maggio

Birthday: 1998-01-20

Address: 359 Kelvin Stream, Lake Eldonview, MT 33517-1242

Phone: +577037762465

Job: Product Hospitality Supervisor

Hobby: Gardening, Web surfing, Video gaming, Amateur radio, Flag Football, Reading, Table tennis

Introduction: My name is Manual Maggio, I am a thankful, tender, adventurous, delightful, fantastic, proud, graceful person who loves writing and wants to share my knowledge and understanding with you.