|
Device code phishing occurs when a threat actor initiates the device code authentication workflow instead of a legitimate device requesting access. The threat actor submits a device code request to a legitimate service, such as Microsoft, implying that they are on a device without a keyboard. The service then generates a device code. The threat actor identifies their target and creates phishing campaigns tailored to the target’s role. The recent phishing emails contain various lures, such as shared documents for review, invoices, statements, regulation updates, settlement claims, project documents, encrypted messages, and security notices. The threat actor ultimately sends the target the device code via a phishing link in the email body or attachment.
|