Skip to content

Security1 publisher2 min readPublished

eSentire finds GhostCode phishing Microsoft device codes through web contact forms

eSentire's Threat Response Unit says the GhostCode kit abuses Microsoft's OAuth 2.0 device authorization grant, and the lure reached targets in late August 2026 as a procurement inquiry filed through a company's own web form.

The Watch · Security desk

Illustration accompanying eSentire finds GhostCode phishing Microsoft device codes through web contact forms

What happened

  • eSentire's Threat Response Unit identified an active device code phishing campaign in late August 2026, with the lures arriving through the targets' own web contact forms.
  • eSentire tracks the kit as GhostCode, naming it for GHOSTnet ASN activity seen during device enrollment and for the obfuscated code hidden inside the HTML lure.
  • Kits of this class abuse the OAuth 2.0 device authorization grant flow to gain access to Microsoft accounts.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Contact form traffic lands with sales and support staff, so the people handling a GhostCode lure are the ones paid to respond to unknown senders and the ones with least reason to treat a stranger's request as hostile.
  • decision Scoping the device authorization grant to named applications is a tenant policy edit. Identity admins own the call, and the change lands without a vendor fix or a maintenance window.
  • constraint One vendor and one campaign falls short of the incident volume that would justify a restriction on its own, so the case for gating the grant has to be argued from how the flow works.

A web contact form is a public submission box a company keeps open on purpose. The submission lands in whatever queue takes sales and procurement inquiries, and it is read by someone whose job is answering people they have never met. eSentire says the operators posed as a procurement officer at a legitimate business [2], a pretext fitted to that channel.

The kit's name carries the two artifacts eSentire found. The researchers write that "Ghost" refers to "GHOSTnet ASN activity observed during device enrollment and the hidden, obfuscated code within the HTML lure" [4], and that "Code" refers to the kit's abuse of Microsoft device code authorization [5]. The enrollment detail is the useful half for anyone hunting. Registration traffic seen in one hosting provider's address space is a value that sits in tenant sign-in logs, alongside the application completing the grant.

What is on the record is one campaign, identified by one vendor, dated to late August 2026 [1][9]. eSentire published the work as "GhostCode: Dissecting a Novel Device Code Phishing Kit" [7], and did not publish victim counts or say whether operators other than this crew hold the kit.

The policy question turns on how the flow is designed. Device code phishing kits abuse the OAuth 2.0 device authorization grant to gain access to Microsoft accounts [6], so the target is a grant type a tenant either allows or does not. eSentire describes GhostCode as a kit with obfuscated code inside the lure page [3][4]. A kit is reusable by whoever holds it. Reuse is what separates an operator's technique from a supply.

An admin can answer the scoping question from data already collected: which applications in the tenant completed the device authorization grant in the last 90 days, and for which users. The grant is only needed by the applications on that list. Anything that can still complete the flow is reachable by anyone running the kit eSentire calls GhostCode [3]. eSentire says it protects more than 2,000 organizations across more than 35 industries [8], and out of that estate this campaign surfaced through contact forms [1].

What to watch

  • Whether a second vendor or a national CERT reports the same kit under its own tracking name.
  • Whether eSentire publishes indicators: the GHOSTnet ranges used for enrollment and the application IDs completing the grant.
  • Whether the same operators switch delivery from contact forms to email or chat once form submissions get filtered.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories