Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse

Cybersecurity researchers have identified a sophisticated phishing campaign exploiting Microsoft's device code flow to hijack Microsoft 365 accounts across 340+ organizations. The attack is particularly dangerous as it grants persistent access that bypasses password resets.
Cybersecurity researchers are calling attention to an active device code phishing campaign that's targeting Microsoft 365 identities across more than 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany.
The activity, per Huntress, was first spotted on February 19, 2026, with subsequent cases appearing at an accelerated pace since then. Notably, the campaign leverages Cloudflare Workers redirects with captured sessions redirected to infrastructure hosted on a platform-as-a-service (PaaS) offering called Railway, effectively turning it into a credential harvesting engine.
Construction, non-profits, real estate, manufacturing, financial services, healthcare, legal, and government are some of the prominent sectors targeted as part of the campaign.
Device code phishing refers to a technique that exploits the OAuth device authorization flow to grant the attacker persistent access tokens, which can then be used to seize control of victim accounts. What's significant about this attack method is that the tokens remain valid even after the account's password is reset.
Huntress has since attributed the Railway attack to a new phishing-as-a-service (PhaaS) platform known as EvilTokens, which made its debut last month on Telegram. Besides advertising tools to send phishing emails and bypass spam filters, the EvilTokens dashboard provides customers with open redirect links to vulnerable domains to obscure the phishing links.
The phishing page employs several anti-analysis techniques, such as disabling right-click functionality, blocking keyboard shortcuts for developer tools (F12, Ctrl+Shift+I), and initiating infinite debugger loops if it detects active analysis tools. Users are advised to scan sign-in logs for suspicious Railway IP logins and revoke refresh tokens for any affected accounts.
Source: The Hacker News















