eSentire TRU uncovered GhostCode, an active device code phishing campaign delivered through web contact forms and disguised business outreach, which abused Microsoft device code authorization to steal tokens, register devices, and obtain a Primary Refresh Token in under 78 seconds. The campaign used layered HTML obfuscation, WeTransfer-hosted lures, compromised or lookalike infrastructure, residential proxy rotation, and Microsoft/Cloudflare trust signals to bypass detection and complete post-compromise access. #GhostCode #GHOSTnet #EvilTokens #Storm2372 #MicrosoftAuthBroker #CloudflareTurnstile #WeTransfer #Salesforce #BJsWholesaleClub
Keypoints
- eSentire TRU detected an active device code phishing campaign in late August 2026 and named the kit âGhostCode.â
- Attackers used web contact forms and posed as procurement staff from legitimate businesses to build trust.
- The lure chain included Salesforce outreach, a WeTransfer link, and a password-gated HTML file masquerading as âFlipBook.â
- The HTML lure used three evasion layers: junk padding, character-level HTML comment injection, and AES-256-GCM encrypted redirect logic.
- Victims were redirected through bot checks and Cloudflare Turnstile to a device code phishing page that abused Microsoftâs OAuth 2.0 device authorization flow.
- After MFA completion, attackers obtained tokens, registered three devices in 78 seconds, and harvested a Primary Refresh Token and email access.
- TRU responded by revoking tokens, resetting credentials, disabling attacker-enrolled devices, and publishing hunting guidance and KQL.
MITRE Techniques
- [T1656 ] Impersonation â Threat actors posed as a procurement officer from a legitimate company to establish trust and drive follow-up contact. (âposed as a procurement officer of a legitimate businessâ)
- [T1566.002 ] Spearphishing Link â The victim received a WeTransfer link that led to a password-gated HTML lure. (âThe follow-up email contained a WeTransfer link to a password-gated HTML attachment.â)
- [T1027 ] Obfuscated Files or Information â The HTML lure used junk padding, comment injection, and encrypted redirect data to evade scanning and classification. (âjunk paddingâ, âHTML comments injected between individual charactersâ, âthe actual payload ⌠is never present in plaintextâ)
- [T1102 ] Web Service â The campaign used Salesforce contact forms and WeTransfer as delivery and engagement infrastructure. (âsubmitted a seemingly innocuous inquiry through Salesforceâ, âcontained a WeTransfer linkâ)
- [T1090 ] Proxy â The phishing flow activated residential/rotating proxies to align attacker traffic with victim geography. (âactivate a proxy through FlashProxy[.]io, a residential/rotating proxy providerâ)
- [T1056.001 ] Input Capture: Keylogging â The lure captured the user-entered device code via a Microsoft sign-in flow that the victim completed on the attackerâs behalf. (âprompted the victim to enter an attacker-supplied user codeâ)
- [T1078 ] Valid Accounts â The attackers used stolen authentication tokens and a Primary Refresh Token to access Microsoft resources as the victim. (âobtain authentication tokensâ, âThe attacker obtained a Primary Refresh Token (PRT)â)
- [T1136.001 ] Create Account: Local Account â Not mentioned.
- [T1136 ] Create Account â The actors registered multiple devices under the stolen token to strengthen persistence. (âThey then registered several devicesâ)
- [T1098 ] Account Manipulation â The campaign modified account/device trust by enrolling devices and extending access via token abuse. (âacquired long-living tokensâ, âIntune enrollmentâ)
- [T1021.004 ] Remote Services: SSH â Not mentioned.
- [T1199 ] Trusted Relationship â The lure abused legitimate Microsoft and Cloudflare pages to gain victim trust. (âdirected to Microsoftâs legitimate sign-in pageâ, âserved by legitimate Cloudflare infrastructureâ)
- [T1057 ] Process Discovery â Not mentioned.
- [T1119 ] Automated Collection â The attackers harvested emails after obtaining persistent access. (âharvested emailsâ)
Indicators of Compromise
- [Domains ] impersonation and relay infrastructure â bjssourcing[.]com, chartered.flipbookonlinevault[.]com, account-access-rc3uenqi.elitechiropracticandrehab[.]com, and 2 more domains
- [Email addresses ] disposable registration and persona accounts â jeremyarcher@voewo[.]com, and other voewo[.]com-based personas
- [File names ] HTML lure and decoy content â 3arhCt9c0p.html, and the decoy NDA PDF
- [IP addresses ] attacker/proxy activity observed during token abuse â 82.33.39[.]74, 5.230.71[.]51, and other 7 IPs
- [Device IDs ] attacker-enrolled Windows/Azure AD devices â 4e537622-2514-48b8-84ed-0139549cfab0, 6c290bcc-62d3-40bd-a774-816109af6729, and 5e83a216-f67e-43b8-a129-f67666a001dd
- [Microsoft App ID ] OAuth client used for device code requests â 29d9ed98-a469-4536-ade2-f981bc1d605e
- [User agents ] post-compromise automation and filtering â python-requests/2.34.2, Microsoft Office/16.0 (Windows NT 10.0; Microsoft Outlook 16.0.17425; Pro
- [URLs/paths ] phishing and relay endpoints â /api/harvester?action=geoip, /api/harvester?action=get_code, /turnstile?return_url=âŚ, and /api/harvester?action=poll
- [User codes ] device code phishing values injected into the lure â CHGNHX34Z
Read more: https://www.esentire.com/blog/ghostcode-dissecting-a-novel-device-code-phishing-kit