Device Code Phishing: Technical Analysis and Proactive Hunting via Netlas
netlas.io | research | #threat-hunting | #phishing | #oauth | #token-theft | #netlas | #device-code-phishing
Summary
Device-code phishing abuses the OAuth RFC 8628 flow: victims enter codes on genuine Microsoft pages while tokens land with attackers — plus template comparisons and Netlas hunting patterns.
- Published
- Collected
Skip to content