Device Code Phishing Is Back: Inside the New BEC Frontier
There is no fake login page to spot. The login is real. The domain is microsoft.com. The MFA prompt is genuine. The only attacker-controlled surface is the social-engineering page that hands the victim a code to type into Microsoft’s own site. Even careful users get caught. And once they do, forensics gets harder.
In device code flow, attacker and victim share the same session ID, so the usual playbook of filtering the Unified Audit Log by session breaks down.
Join Eye Security’s threat research and forensics experts, together with Microsoft GTM Lead Jeroen Jansen, for a live session on why this technique is resurging, how the latest kits (including encrypted-payload loaders) evade static detection, how to investigate a shared-session compromise using linkable token identifiers, and where to intercept the attack: on the page that delivers the code, before any token is issued.
“We balanced Eye Security’s costs against the value they would bring and the ROI stood up to scrutiny. The solution we now have in place prevents incidents and works with proven EDR and AI technology, which gives us peace of mind.”
View Case StudyYour Eye Cyber Guard, in detail.
Your cyber resilience in one live view.
Eye Platform brings together Fortify, Detect, Respond, and Insure, moving as one. Eye Cyber Guard is our core MDR product, delivered through Eye Platform, alongside four connected capabilities: