Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft 365 OAuth device code phishing campaign

Campaign
First reported
Last updated
Happening score
H score 32
3 unique sources, 4 articles

Summary

Hide ▲

Microsoft 365 device-code phishing activity in June 2025 into July 2026 used the legitimate Microsoft device login flow and Evilginx-based tooling to capture tokens and enable account takeover. Lexfo tied a misconfigured Python HTTP server on a Budapest VPS to three phishing actors, including codemado and saroula01. The largest operation, saroula01's Device Code Flow campaign, ran from June 2025, reached 218 confirmed victims across 12 countries, and refreshed stolen tokens up to 25 times to preserve access.

Related Happenings

The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster

Threat Actor Meta
H score14 First: 13.07.2026 18:30 Last: 13.07.2026 18:30 Sources 1

How related: Lexfo also connected codemado's MaDoO Blaster to The Quarry, a phishing-as-a-service (PaaS) ecosystem documented by SOCRadar in June and run by an actor known as RockyBelling, who promoted the tool to his customers.

About this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...

Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking

Threat Actor Meta
H score36 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

O-UNC-066 / Pink Microsoft Entra passkey vishing campaign

Campaign
H score37 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...

Microsoft Azure CLI password-spray campaign using ROPC

Campaign
H score24 First: 01.07.2026 08:46 Last: 01.07.2026 08:46 Sources 1

About this happening: A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...

Timeline

  1. 13.07.2026 18:30 1 articles · 2d ago

    saroula01 Microsoft 365 device-code campaign reaches 218 victims

    Campaign Scope Update

    Lexfo reconstructed a deleted configuration file and internal bot timestamps showing saroula01's OAuth Device Code Flow framework had been active since June 2025, with 218 confirmed victims across 12 countries and captured tokens refreshed up to 25 times to preserve access.

    Show sources
  2. 19.12.2025 19:19 4 articles · 6mo ago

    Microsoft 365 OAuth device code phishing campaign

    Initial Disclosure

    The earliest visible phase used document-sharing lures and localized company branding to push victims into Microsoft's device-code login flow. Entering the code there authorized attacker access to the account.

    Show sources