Microsoft 365 OAuth device code phishing campaign
Campaign
Summary
Hide ▲
Show ▼
Microsoft 365 device-code phishing activity in June 2025 into July 2026 used the legitimate Microsoft device login flow and Evilginx-based tooling to capture tokens and enable account takeover. Lexfo tied a misconfigured Python HTTP server on a Budapest VPS to three phishing actors, including codemado and saroula01. The largest operation, saroula01's Device Code Flow campaign, ran from June 2025, reached 218 confirmed victims across 12 countries, and refreshed stolen tokens up to 25 times to preserve access.
Related Happenings
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
How related:
Lexfo also connected codemado's MaDoO Blaster to The Quarry, a phishing-as-a-service (PaaS) ecosystem documented by SOCRadar in June and run by an actor known as RockyBelling, who promoted the tool to his customers.
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaHow related: Lexfo also connected codemado's MaDoO Blaster to The Quarry, a phishing-as-a-service (PaaS) ecosystem documented by SOCRadar in June and run by an actor known as RockyBelling, who promoted the tool to his customers.
About this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
Campaign
H score37
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
CampaignAbout this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
Microsoft Azure CLI password-spray campaign using ROPC
Campaign
H score24
First: 01.07.2026 08:46
Last: 01.07.2026 08:46
Sources 1
About this happening:
A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
Microsoft Azure CLI password-spray campaign using ROPC
CampaignAbout this happening: A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
Timeline
-
13.07.2026 18:30 1 articles · 2d ago
saroula01 Microsoft 365 device-code campaign reaches 218 victims
Campaign Scope UpdateLexfo reconstructed a deleted configuration file and internal bot timestamps showing saroula01's OAuth Device Code Flow framework had been active since June 2025, with 218 confirmed victims across 12 countries and captured tokens refreshed up to 25 times to preserve access.
Show sources
- Open Directory Exposes Three Evilginx Phishing Operators — www.infosecurity-magazine.com — 13.07.2026 18:30
-
19.12.2025 19:19 4 articles · 6mo ago
Microsoft 365 OAuth device code phishing campaign
Initial DisclosureThe earliest visible phase used document-sharing lures and localized company branding to push victims into Microsoft's device-code login flow. Entering the code there authorized attacker access to the account.
Show sources
- Microsoft 365 accounts targeted in wave of OAuth phishing attacks — www.bleepingcomputer.com — 19.12.2025 19:19
- Microsoft 365 accounts targeted in wave of OAuth phishing attacks — www.bleepingcomputer.com — 19.12.2025 19:19
- DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts — thehackernews.com — 07.07.2026 18:14
- Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 — thehackernews.com — 13.07.2026 10:30