Device Code Phishing

What is Device Code Phishing?

Device code phishing exploits a legitimate authentication mechanism designed for devices with limited input capabilities, such as smart TVs and IoT devices, that cannot easily display a web browser for standard login. In the normal flow, a device displays a short code and directs the user to enter it on a trusted authentication portal (such as Microsoft’s login page) to authorize the device. In the attack variant, the adversary generates the device code and delivers it to the victim through a phishing email, a WhatsApp message, or a vishing call, instructing them to enter it at the legitimate authentication URL. Because the victim authenticates on the real identity provider’s page and completes real MFA, the resulting session token grants the attacker access without any credential ever touching attacker-controlled infrastructure. CrowdStrike’s 2026 Threat Hunting Report documented a 15-fold increase in monthly device code phishing attempts in the first half of 2026. The technique was first operationalized by Russian state-sponsored group Storm-2372 in 2024 and has since been commoditized through phishing-as-a-service platforms including EvilTokens and Kali365. Both nation-state actors (notably Cozy Bear) and eCrime groups now use dedicated device code and session management infrastructure at scale.

 

Business Impact

Device code phishing is exceptionally difficult to detect because the authentication occurs entirely on legitimate infrastructure. There is no fake login page to blocklist, no suspicious domain for URL scanning to flag, and the victim’s MFA functions as designed. The attacker receives a valid session token indistinguishable from a legitimate login. Traditional anti-phishing controls that scan for malicious URLs or analyze email links are ineffective against an attack where the only link points to Microsoft’s real authentication portal. Organizations that have invested in phishing-resistant MFA may still be vulnerable if their conditional access policies do not restrict or monitor device code flows specifically.

 

Allure Security's Approach

Allure Security monitors for the external impersonation infrastructure that supports device code phishing campaigns, including phishing pages that present device codes with instructions for victims, social engineering lures impersonating IT support or collaboration platforms, and the downstream brand impersonation that follows successful account compromises. By detecting these components at the campaign level rather than at the individual authentication event, Allure provides visibility into attack infrastructure that endpoint and identity security tools operating inside the trust boundary cannot see.

See the threats targeting your brand right now

Get a customized assessment showing active impersonation, phishing infrastructure, and exposed credentials specific to your organization. No commitment required.