Device code phishing, a method involving the misuse of the OAuth 2.0 device authorization grant to appropriate access tokens, has transitioned from being a niche technique to a significant threat in 2026. Initially intended for devices with limited input options, this flow is now exploited across various applications, notably in command-line interface logins.
The Rapid Evolution of Device Code Phishing
First recognized in 2020, device code phishing remained largely unexplored until nation-state actors like Storm-2372 adopted it in 2024. By 2025, it gained traction among cybercriminals, notably ShinyHunters, which targeted Salesforce at scale. The threat intensified with the introduction of the EvilTokens kit in early 2026, leading to a surge in phishing campaigns. Microsoft reported a significant increase in daily campaigns, and more than 7 million attacks were recorded in a four-week span. This prompted the FBI to issue an advisory on the threat posed by the Kali365 phishing kit.
Industrialization and Proliferation in Phishing Ecosystems
The commercial viability of device code phishing has led to its inclusion in phishing-as-a-service (PhaaS) offerings. Kits like Tycoon2FA and Kali365 have integrated device code phishing alongside other techniques, reflecting a broader trend of commoditization. The rapid development and distribution of these kits, facilitated by AI-assisted methods, have enabled their widespread adoption. The pattern mirrors the trajectory of adversary-in-the-middle (AiTM) phishing, albeit at an accelerated pace.
Widespread Implications Beyond Microsoft
Although Microsoft remains the primary target, the cross-platform nature of the OAuth 2.0 device authorization grant suggests that other platforms could soon face similar threats. Applications like Salesforce, GitHub, and AWS, which implement the device code flow, are potential targets. Attackers are shifting focus from the authentication process to the authorization layer, exploiting less-protected areas.
As phishing kits proliferate, detection strategies must evolve. Traditional security measures often fall short in identifying device code phishing due to the legitimate nature of the login URLs involved. Effective mitigation requires focusing on the behavioral signatures of phishing activities at the browser level, where attacks are more visible.
For a deeper understanding of device code phishing, including a technical breakdown and a demonstration of the attack process, Push Security offers a comprehensive webinar. The company’s AI-native security tools provide critical insights and defense mechanisms against evolving threats.
