Upcoming Webinar

Tradecraft Tuesday | June 2026

On Valentine’s Day 2025, Storm-2372 Russian threat actors leveraged OAuth device code flow to hijack Microsoft Entra device registration to obtain the Primary Refresh Token (PRT) and persistence. In March 2026, the EvilTokens campaign used device code phishing and Railway to automate large-scale attacks.

OAuth device code phishing is being used increasingly by threat actors to hijack OAuth tokens because of its phishing-friendly user codes, "MFA-bypass", by design token delivery over REST APIs, and ease-of-abuse.

We'll look at device code phishing variations across different apps and stacks, including the impersonation of first-party apps requiring minimal attacker infrastructure, pivoting across a user's SSO apps/data, an analysis of Storm-2372 tradecraft involving PRT hijacking and Windows Hello for Business (WHfB) persistence. We also delve into bypasses of the 15-minute code expiration and delivery mechanisms including BITM/MITM, QR codes, smishing, and chat-based lures