Phishing campaigns targeting Microsoft 365 users are becoming more difficult to detect as attackers increasingly rely on Microsoft’s legitimate authentication infrastructure instead of counterfeit login pages. According to new research from Check Point, the shift allows threat actors to take advantage of the trust users place in Microsoft’s services while avoiding many of the indicators traditionally associated with phishing websites.

 

 

Rather than attempting to steal usernames and passwords through fake sign-in pages, the observed campaigns abuse Microsoft’s device code authentication process, a feature designed for devices that cannot easily display a full login interface or accept complex user input. Because victims are directed to authentic Microsoft domains during the sign-in process, they are less likely to question the request, and security controls that rely on identifying fraudulent websites may have fewer opportunities to intervene.

Check Point found that attackers first contact potential victims through phishing emails crafted to appear as legitimate business communications. Instead of asking recipients to verify an account or reset a password, the messages encourage them to complete what appears to be a routine authentication step. The victim is instructed to enter a device code through Microsoft’s genuine sign-in portal, unknowingly authorising a session initiated by the attacker rather than one associated with their own device.

Once the approval is granted, the attacker can obtain authentication tokens that provide access to the victim’s Microsoft 365 environment without needing the account password. Depending on the permissions granted and the account’s configuration, this access may allow the threat actor to view emails, interact with cloud resources, and maintain access until the issued tokens expire or are revoked.

The research highlights how this technique differs from conventional phishing. Instead of defeating a user’s ability to recognise a fake website, the attackers exploit a legitimate feature exactly as it was designed to operate, making the social engineering component of the attack far more important than technical deception. As a result, users may believe they are completing a normal Microsoft sign-in because every page they encounter belongs to Microsoft.

According to Check Point, the growing use of trusted cloud services in phishing operations reflects a broader evolution in cybercrime. As organisations improve their ability to detect spoofed domains and cloned login portals, attackers are increasingly shifting toward abusing legitimate platforms and authentication workflows to achieve the same objective while reducing the likelihood of detection.

The researchers recommend that organisations raise awareness of device code phishing among employees and closely monitor authentication activity for unexpected device authorisations. Users should be cautious whenever they receive unsolicited requests to enter a device code, even if the sign-in page is hosted on an authentic Microsoft domain. Security teams should also review token-based authentication events and investigate unusual authorisation activity, as the absence of a fake website no longer guarantees that a sign-in request is legitimate.

Leave a Reply