Skip to content
  • facebook.com
  • twitter.com
  • t.me
  • instagram.com
  • youtube.com
Prep Music Log
Subscribe
  • Home
  • Tech
  • Music
  • Apple
  • Gaming
  • Home
  • Biz & IT
  • What is device code phishing, and why are Russian spies so successful at it?
What is device code phishing, and why are Russian spies so successful at it?
Posted inaccount takeovers Biz & IT device code authorization phishing russia Security

What is device code phishing, and why are Russian spies so successful at it?

Posted by Samara February 14, 2025

Researchers have uncovered a sustained and ongoing campaign by Russian spies that uses a clever phishing technique to hijack Microsoft 365 accounts belonging to a wide range of targets, researchers warned.

The technique is known as device code phishing. It exploits “device code flow,” a form of authentication formalized in the industry-wide OAuth standard. Authentication through device code flow is designed for logging printers, smart TVs, and similar devices into accounts. These devices typically don’t support browsers, making it difficult to sign in using more standard forms of authentication, such as entering user names, passwords, and two-factor mechanisms.

Rather than authenticating the user directly, the input-constrained device displays an alphabetic or alphanumeric device code along with a link associated with the user account. The user opens the link on a computer or other device that’s easier to sign in with and enters the code. The remote server then sends a token to the input-constrained device that logs it into the account.

Device authorization relies on two paths: one from an app or code running on the input-constrained device seeking permission to log in and the other from the browser of the device the user normally uses for signing in.

A concerted effort

Advisories from both security firm Volexity and Microsoft are warning that threat actors working on behalf of the Russian government have been abusing this flow since at least last August to take over Microsoft 365 accounts. The threat actors masquerade as trusted, high-ranking officials and initiate conversations with a targeted user on a messenger app such as Signal, WhatsApp, and Microsoft Teams. Organizations impersonated include:

Last updated on February 15, 2025
Samara
View All Posts

Post navigation

Previous Post
No penalties even when deputies share a woman’s nudes after an illegal phone search No penalties even when deputies share a woman’s nudes after an illegal phone search
Next Post
Louisiana officially ends mass vaccinations as RFK Jr. comes to power Louisiana officially ends mass vaccinations as RFK Jr. comes to power

Recent Posts

  • 11 things you probably didn’t know the Switch 2 can do
  • “Godfather” of AI calls out latest models for lying to users
  • “Free Roam” mode is Mario Kart World’s killer app
  • Milky Way galaxy might not collide with Andromeda after all
  • Tuesday Telescope: A time-lapse from orbit reveals treasures below

Recent Comments

No comments to show.

Archives

  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • September 2024
Copyright 2025 — Prep Music Log. All rights reserved. Bloghash WordPress Theme
Scroll to Top