Kaspersky has released a report detailing a phishing campaign that abuses Microsoft’s authentication mechanism to steal user credentials.
The phishing campaign spanned from early April to mid-May 2026, disguised as a notice from a law firm. Consequently, attackers aimed to access victim data by hijacking accounts.
The Mechanics of the Phishing Campaign
The targeted mechanism is the OAuth 2.0 Device Authorization Grant, which allows users to log into Microsoft accounts on devices with limited input capabilities. Specifically, users can paste a code or scan a QR code on a secondary device like a smartphone. However, this convenience creates an opportunity for attackers to hijack accounts using stolen refresh tokens.

Step-by-Step Attack Process
Attackers initiated the process by sending emails disguised as legal communications containing a password-protected PDF file. Once the victim opened the document and entered the password, they were directed to a webpage listing several documents. Notably, viewing these files required clicking a link that led to a legitimate Microsoft address.
The URL parameters redirected the user from the official platform to a fake portal designed to mimic a legal document viewer. This page featured multiple CAPTCHAs to filter out security bots that check websites for threats. After passing these checks, the user received a one-time code that the attackers had already generated.
Clicking the code copied it to the clipboard and redirected the user to the actual Microsoft authentication page. The victim then pasted the code, completing the multifactor authentication process. As a result, the attackers obtained the session tokens.
Impact on Corporate Data
Once the attackers secured the session tokens, they gained unauthorized access to the victim’s digital environment. Specifically, they could read and send emails from the compromised mailbox. Furthermore, the attackers could exfiltrate files from OneDrive and access private Teams conversations.
These actions compromise sensitive corporate communications and intellectual property. Organizations must therefore monitor active sessions and review access logs regularly. Meanwhile, security teams should educate employees on the risks of copying unexpected authentication codes.
Security Recommendations and Mitigation
Roman Dedenok, an anti-spam expert at Kaspersky, stated that threat actors do not always rely on harvesting credentials or deploying malware. Instead, they can weaponize legitimate tools. He advised enterprise teams to evaluate the business necessity of the Device Code Flow and disable it if not required.
To establish a defense, organizations should deploy email security solutions. For corporate users, Kaspersky Security for Mail Server offers multi-layered defense mechanisms powered by machine learning. Additionally, individual users can use Kaspersky Premium for anti-phishing features to prevent a phishing campaign from compromising their personal devices.
The security firm, founded in 1997, continues to track these evolving digital threats globally. Detailed information regarding this specific activity is available in the full report published on Securelist.





