Device Code Phishing: The Threat That Renders MFA Useless
Device code phishing exploits OAuth 2.0 to bypass MFA, even passkeys. Learn how automated kits are stealing tokens in millions of attacks globally.
Illustrative image generated with AI
If multi-factor authentication is no longer a sufficient barrier, the reason is device code phishing. This technique exploits the OAuth 2.0 device authorization grant (RFC 8628) to steal access tokens from an already authenticated session, bypassing any second factor: passkeys, hardware tokens, OTP codes. No longer a curiosity presented in 2020, it has become an industrial-scale phenomenon, fueled by ready-made kits and increasingly generated with the help of language models.
How MFA Is Bypassed, Even with Passkeys
The mechanism completely sidesteps the authentication phase by exploiting the trust placed in the device authorization flow. The attacker initiates the device code process on a service (for example, Microsoft Entra ID), obtaining an alphanumeric code and a verification URL. They then trick the victim into visiting that URL—a perfectly legitimate address, such as login.microsoftonline.com—and entering the code. Seeing the provider’s genuine login page, the user signs in with their credentials and completes MFA, unknowingly granting OAuth consent. At that point, the attacker’s client receives tokens (access and refresh) that provide persistent access, without a login page ever being cloned.
Classic defenses based on recognizing fake URLs are ineffective. The entire chain takes place on trusted domains; the phishing consists of convincing someone to type a code, not stealing a password.
The Escalation: From Nation-State to 7 Million Attacks in Four Weeks
After the first tentative descriptions in 2020, device code phishing appeared in the field with nation-state actors in 2024. The real industrialization arrived in 2025 with the ShinyHunters campaign against Salesforce: over 1,000 organizations compromised and 1.5 billion records exfiltrated. It was the signal that the technique had become a mass-market weapon.
In February 2026, the EvilTokens kit further lowered the barrier to entry, making the attack repeatable even by criminals without advanced skills. By April, Microsoft was reporting 10 to 15 new campaigns per day, and in the four frantic weeks that followed, Barracuda counted 7 million attacks. In May, the Tycoon2FA PhaaS platform natively integrated the device code flow. Today, Push Security tracks more than 25 dedicated kit families—an ecosystem now joined by kits like ARToken, capable of obtaining Primary Refresh Tokens (PRTs) to ensure persistence, mailbox access, SharePoint exfiltration, and automated BEC.
The FBI issued a standalone alert on the Kali365 kit, the first U.S. federal communication dedicated to a specific phishing-as-a-service offering. Meanwhile, AI-assisted generation—so-called “vibe coding”—accelerates the creation of new variants, making the threat increasingly difficult to contain.
No Longer Just Login: The Paradigm Shift Toward Authorization
The phenomenon is part of a broader trend shifting the target from authentication to authorization. Techniques like ConsentFix, which appeared at the end of 2025, aim directly at OAuth consent abuse, and device code phishing itself operates at the permission-granting level rather than credential capture. The result is a class of attacks that traditional intrusion detection systems, tuned for the login phase, fail to intercept.
Today, 99% of observed attacks target Microsoft accounts, but the device code flow is also supported by GitHub, AWS, and other cloud providers, automatically becoming potential targets. The compromise goes beyond initial access: stealing a PRT allows threat actors to maintain presence in the tenant for long periods. And the data shows the damage is already real, not just a projection.
What an Organization Can Do
Since MFA is no longer a shield, defenses must shift to authorization control.
- Limit the device grant: disable the device authorization flow for all applications that do not genuinely need it. Where that’s not possible, apply Conditional Access policies that block device code requests from unrecognized IPs, devices, or contexts.
- Monitor OAuth consents: pay attention to every permission grant to unknown apps, even if the underlying authentication appears legitimate. Platforms like Microsoft Entra ID allow you to enable alerts on new consents and automatically revoke them through consent phishing detection.
- Train users: explain that they must never enter a pairing code received via email, SMS, or chat, even if the link leads to a familiar login page. The presence of MFA is not a guarantee of security.
- Integrate authorization into the SOC: introduce detection rules that observe anomalous patterns in OAuth flows and refresh tokens. Defenses focused solely on authentication are blind to an attack that begins after the user has already logged in.
Device code phishing is not a marginal evolution: it is evidence that the game has definitively moved beyond the password perimeter. Ignoring this shift means leaving the door open after reinforcing the lock.
Sources
This article is an original reworking based on the sources below.




