Huntress found legitimate remote management software abused in 45% of the endpoint incidents it logged in the first quarter of 2026. A rogue copy can behave like IT's approved one, so defenders have to know which tools are sanctioned and how each install arrived.
Reality
- Evidence45
- Adoption55
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
ANY.RUN tied 351 sandbox analyses to CSuite, a phishing operation that steals Microsoft 365 sessions or installs ScreenConnect or Action1 for remote access. Resetting credentials leaves the remote-access half of an intrusion in place.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives80
- Confidence45
Google's threat intelligence team ties three suspected Russian clusters to abuse of Google OAuth, app passwords and device linking. MFA completes normally, so consent telemetry is the control.
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
Microsoft has tracked passkey- and SSO-themed help desk impersonation since May 2026, with the calls steering employees into adversary-in-the-middle proxies and device-code grants that hand over live Microsoft 365 sessions.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence60
Microsoft's Digital Crimes Unit and its partners pulled down the EvilTokens phishing service about seven months after it launched, and British police arrested its two suspected operators. The authentication technique it sold survives on other platforms.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 60%
- Investor
- Investor 15%
Reality
- Evidence66
- Adoption58
- Hype gap+18
- Incentives62
- Confidence64
The OAuth device authorization grant was built for smart TVs and printers. Kits such as EvilTokens use it to get victims to approve an attacker's sign-in on a page that really is Microsoft's, MFA included.
Reality
- Evidence55
- Adoption20
- Hype gap+12
- Incentives70
- Confidence55
Microsoft says the phishing-as-a-service platform reached more than 12,000 inboxes at over 10,000 organizations in seven months by abusing a legitimate OAuth flow, and its Digital Crimes Unit has now disrupted the infrastructure behind the service.
Reality
- Evidence58
- Adoption62
- Hype gap+20
- Incentives76
- Confidence57
eSentire's Threat Response Unit says the GhostCode kit abuses Microsoft's OAuth 2.0 device authorization grant, and the lure reached targets in late August 2026 as a procurement inquiry filed through a company's own web form.
Publishers:esentire.com
Reality
- Evidence48
- Adoption32
- Hype gap+20
- Incentives78
- Confidence45
The device code phishing cluster Microsoft disclosed in February 2025 is now assessed as an initial access arm of Midnight Blizzard. The sign-in flow the campaign abused works as designed, so the remedy is configuration.
Reality
- Evidence60
- Adoption55
- Hype gap−12
- Incentives72
- Confidence58
eSentire says a phishing kit called GhostCode used Microsoft's device-code flow to register three devices within 77 seconds of a victim completing MFA, and one of them stayed enrolled in Intune until it was explicitly removed.
Reality
- Evidence58
- Adoption30
- Hype gap+12
- Incentives60
- Confidence55
ANY.RUN says the kit lures staff with Teams, DocuSign and Dropbox pages, walks them through a genuine device code sign-in, and then takes the access and refresh tokens to register a device of its own.
Reality
- Evidence25
- Adoption20
- Hype gap+45
- Incentives85
- Confidence60
Microsoft has tracked intrusions since May in which callers posing as IT told employees a passkey update was due, then steered them to a phishing page or a device-code prompt. The enrollment step is where the chain starts.
Reality
- Evidence55
- Adoption35
- Hype gap−5
- Incentives60
- Confidence58
Microsoft's researchers describe a device code phishing campaign that minted fresh codes the moment a target clicked, defeating the expiry that used to hold these attacks down. The flow it abuses is only needed by hardware that cannot show a login page.
Reality
- Evidence55
- Adoption45
- Hype gap+20
- Incentives65
- Confidence60
Microsoft Security Research describes callers posing as IT staff to get a Microsoft 365 session relayed or minted to their own client. The lasting damage comes from the MFA method they then register.
Reality
- Evidence55
- Adoption40
- Hype gap+15
- Incentives55
- Confidence55
Wiz says rogue device registrations are drifting toward benign names, while nearly one in seven Entra tenants saw such an attack in 90 days. Naming strings were never the signal.
Reality
- Evidence42
- Adoption55
- Hype gap+30
- Incentives78
- Confidence45