Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GhostCode Phishing Kit Evades Microsoft MFA to Hijack Accounts

GhostCode Phishing Kit Evades Microsoft MFA to Hijack Accounts

Posted on September 16, 2026 By CWS

The GhostCode phishing kit has emerged as a powerful threat, enabling attackers to bypass Microsoft 365’s multi-factor authentication (MFA) and seize control of user accounts in mere seconds. Unlike traditional phishing methods that rely on password theft, GhostCode manipulates its victims into authorizing fraudulent logins to gain unauthorized access.

Deceptive Tactics and Initial Discovery

The GhostCode scam begins with seemingly benign messages submitted via business contact forms. Posing as procurement officials, attackers request recipients sign a non-disclosure agreement, forwarding a WeTransfer link with a password-protected HTML file. This file lures users into a fake Microsoft sign-in process. Cybersecurity firm eSentire identified this scheme in late August, naming it GhostCode for its stealth tactics and GHOSTnet-linked infrastructure usage.

eSentire’s report, shared with Cyber Security News, highlights how the operation ingeniously masquerades as legitimate business communication, thereby reducing suspicion. The attack’s immediacy is alarming; victims complete the authentication process, including MFA, on a genuine Microsoft page, yet unknowingly hand over their access tokens to the attackers.

Mechanics of the GhostCode Attack

GhostCode exploits the OAuth device authorization mechanism, commonly used by devices like smart TVs that lack full sign-in capabilities. By requesting a code with the Microsoft Authentication Broker application ID, attackers integrate this code into a deceptive document portal, urging victims to authenticate it, thereby granting access to their accounts.

The phishing attachment complicates detection. It is filled with extraneous data, obfuscates visible text using HTML comments, and encrypts redirect addresses until the correct password is input. This complexity, combined with targeted outreach via contact forms, echoes tactics from other notorious phishing campaigns but with a more personalized approach.

Countermeasures and Protective Strategies

Given the speed of GhostCode’s attack, simply revoking stolen tokens is insufficient. Researchers advise that security teams should invalidate tokens, reset compromised credentials, and scrutinize newly registered devices. Blocking device-code authentication through Conditional Access is recommended for those who do not need it, with strict exceptions for essential services.

Device compliance controls should be applied where feasible to minimize susceptibility to such phishing attacks. Additionally, organizations should train employees to regard unexpected requests for device code entry as suspicious, especially in light of the growing trend of token-focused session theft attempts.

Conclusion and Future Implications

The GhostCode phishing kit underscores the vulnerabilities inherent in reliance on familiar identity pages rather than detecting technical anomalies. As cloud-based operations grow, the distinction between legitimate and fraudulent access requests becomes crucial. Organizations must remain vigilant and adopt comprehensive security strategies to protect against these advanced phishing threats, ensuring that trust in familiar processes does not become a liability.

Cyber Security News Tags:account security, cyber threats, Cybersecurity, device code phishing, eSentire, GhostCode, MFA bypass, Microsoft 365, OAuth abuse, Phishing

Post navigation

Previous Post: Major WSO2 Flaw Risks Full Admin Control by Hackers
Next Post: Microsoft 365 Faces Global Access Issues with Errors

Related Posts

Jupyter Misconfiguration Flaw Allow Attackers to Escalate Privileges as Root User Jupyter Misconfiguration Flaw Allow Attackers to Escalate Privileges as Root User Cyber Security News
UTG-Q-1000 Group Weaponizing Subsidy Schemes to Exfiltrate Sensitive Data UTG-Q-1000 Group Weaponizing Subsidy Schemes to Exfiltrate Sensitive Data Cyber Security News
Threat Actor Exploited Multiple FortiWeb Appliances to Deploy Sliver C2 for Persistent Access Threat Actor Exploited Multiple FortiWeb Appliances to Deploy Sliver C2 for Persistent Access Cyber Security News
Starbucks Phishing Attack Compromises Employee Data Starbucks Phishing Attack Compromises Employee Data Cyber Security News
New Phishing Attack Leverages Popular Brands to Harvest Login Credentials New Phishing Attack Leverages Popular Brands to Harvest Login Credentials Cyber Security News
Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft 365 Faces Global Access Issues with Errors
  • GhostCode Phishing Kit Evades Microsoft MFA to Hijack Accounts
  • Major WSO2 Flaw Risks Full Admin Control by Hackers
  • German Firm Enhances Security Alert Handling with Cloud Sandbox
  • CISA Highlights Major ScreenConnect Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft 365 Faces Global Access Issues with Errors
  • GhostCode Phishing Kit Evades Microsoft MFA to Hijack Accounts
  • Major WSO2 Flaw Risks Full Admin Control by Hackers
  • German Firm Enhances Security Alert Handling with Cloud Sandbox
  • CISA Highlights Major ScreenConnect Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark