DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign, leveraging collaboration-themed lures, has been observed targeting M365 accounts. The campaign, utilizing a reusable tooling layer called DEBULL, bypasses multi-factor authentication by exploiting a legitimate OAuth 2.0 authentication flow (Device Authorization Grant). Threat actors are using this technique to gain persistent account access and facilitate account takeover, fraud, and potentially disruptive attacks like ransomware. The campaign is linked to a previous Microsoft campaign (Storm-2372) and utilizes a phishing-as-a-service (PhaaS) platform, DEBULL, for orchestration.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
