Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Device Code Phishing: A Rapidly Escalating Threat in 2026

Device Code Phishing: A Rapidly Escalating Threat in 2026

Posted on July 31, 2026 By CWS

Device code phishing, a method involving the misuse of the OAuth 2.0 device authorization grant to appropriate access tokens, has transitioned from being a niche technique to a significant threat in 2026. Initially intended for devices with limited input options, this flow is now exploited across various applications, notably in command-line interface logins.

The Rapid Evolution of Device Code Phishing

First recognized in 2020, device code phishing remained largely unexplored until nation-state actors like Storm-2372 adopted it in 2024. By 2025, it gained traction among cybercriminals, notably ShinyHunters, which targeted Salesforce at scale. The threat intensified with the introduction of the EvilTokens kit in early 2026, leading to a surge in phishing campaigns. Microsoft reported a significant increase in daily campaigns, and more than 7 million attacks were recorded in a four-week span. This prompted the FBI to issue an advisory on the threat posed by the Kali365 phishing kit.

Industrialization and Proliferation in Phishing Ecosystems

The commercial viability of device code phishing has led to its inclusion in phishing-as-a-service (PhaaS) offerings. Kits like Tycoon2FA and Kali365 have integrated device code phishing alongside other techniques, reflecting a broader trend of commoditization. The rapid development and distribution of these kits, facilitated by AI-assisted methods, have enabled their widespread adoption. The pattern mirrors the trajectory of adversary-in-the-middle (AiTM) phishing, albeit at an accelerated pace.

Widespread Implications Beyond Microsoft

Although Microsoft remains the primary target, the cross-platform nature of the OAuth 2.0 device authorization grant suggests that other platforms could soon face similar threats. Applications like Salesforce, GitHub, and AWS, which implement the device code flow, are potential targets. Attackers are shifting focus from the authentication process to the authorization layer, exploiting less-protected areas.

As phishing kits proliferate, detection strategies must evolve. Traditional security measures often fall short in identifying device code phishing due to the legitimate nature of the login URLs involved. Effective mitigation requires focusing on the behavioral signatures of phishing activities at the browser level, where attacks are more visible.

For a deeper understanding of device code phishing, including a technical breakdown and a demonstration of the attack process, Push Security offers a comprehensive webinar. The company’s AI-native security tools provide critical insights and defense mechanisms against evolving threats.

The Hacker News Tags:AI-assisted phishing, authorization attacks, Cybersecurity, device code phishing, EvilTokens, Kali365, MFA, Microsoft, OAuth 2.0, PhaaS, phishing-as-a-service, Push Security, security threats, ShinyHunters, Tycoon2FA

Post navigation

Previous Post: AI Powers Google to Patch Chrome Flaws Swiftly
Next Post: EU Strengthens AI Regulations Amid Global Concerns

Related Posts

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems The Hacker News
Weedhack Malware Targets Minecraft Players via YouTube Weedhack Malware Targets Minecraft Players via YouTube The Hacker News
LockBit, Qilin, and DragonForce Join Forces to Dominate the Ransomware Ecosystem LockBit, Qilin, and DragonForce Join Forces to Dominate the Ransomware Ecosystem The Hacker News
Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor The Hacker News
Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams The Hacker News
Iranian Infy Hackers Reactivate C2 Servers After Internet Blackout Iranian Infy Hackers Reactivate C2 Servers After Internet Blackout The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks
  • EU Strengthens AI Regulations Amid Global Concerns
  • Device Code Phishing: A Rapidly Escalating Threat in 2026
  • AI Powers Google to Patch Chrome Flaws Swiftly
  • Anthropic AI Models Breach Security Systems in Test

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks
  • EU Strengthens AI Regulations Amid Global Concerns
  • Device Code Phishing: A Rapidly Escalating Threat in 2026
  • AI Powers Google to Patch Chrome Flaws Swiftly
  • Anthropic AI Models Breach Security Systems in Test

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark