Tag
high
advisory
Large-Scale OAuth Device Code Phishing Campaign Observed in April 2026
2 rules 1 TTPIn early April 2026, Arctic Wolf tracked a large-scale device code phishing campaign across multiple regions and sectors where threat actors abused OAuth device code flow to trick victims into providing authentication codes.
Azure Active Directory
oauth
device-code
phishing
initial-access
2r
1t
medium
advisory
Entra ID OAuth Device Code Grant by Unusual User
2 rules 3 TTPsAn attacker uses device code authentication in Entra ID to phish users and steal access tokens, leading to unauthorized access and potential defense evasion.
Entra ID
azure
entra-id
device-code
phishing
2r
3t