GhostCode: Dissecting a Novel Device Code Phishing Kit

GhostCode: Dissecting a Novel Device Code Phishing Kit
eSentire TRU uncovered GhostCode, an active device code phishing campaign delivered through web contact forms and disguised business outreach, which abused Microsoft device code authorization to steal tokens, register devices, and obtain a Primary Refresh Token in under 78 seconds. The campaign used layered HTML obfuscation, WeTransfer-hosted lures, compromised or lookalike infrastructure, residential proxy rotation, and Microsoft/Cloudflare trust signals to bypass detection and complete post-compromise access. #GhostCode #GHOSTnet #EvilTokens #Storm2372 #MicrosoftAuthBroker #CloudflareTurnstile #WeTransfer #Salesforce #BJsWholesaleClub

Keypoints

  • eSentire TRU detected an active device code phishing campaign in late August 2026 and named the kit “GhostCode.”
  • Attackers used web contact forms and posed as procurement staff from legitimate businesses to build trust.
  • The lure chain included Salesforce outreach, a WeTransfer link, and a password-gated HTML file masquerading as “FlipBook.”
  • The HTML lure used three evasion layers: junk padding, character-level HTML comment injection, and AES-256-GCM encrypted redirect logic.
  • Victims were redirected through bot checks and Cloudflare Turnstile to a device code phishing page that abused Microsoft’s OAuth 2.0 device authorization flow.
  • After MFA completion, attackers obtained tokens, registered three devices in 78 seconds, and harvested a Primary Refresh Token and email access.
  • TRU responded by revoking tokens, resetting credentials, disabling attacker-enrolled devices, and publishing hunting guidance and KQL.

MITRE Techniques

  • [T1656 ] Impersonation – Threat actors posed as a procurement officer from a legitimate company to establish trust and drive follow-up contact. (‘posed as a procurement officer of a legitimate business’)
  • [T1566.002 ] Spearphishing Link – The victim received a WeTransfer link that led to a password-gated HTML lure. (‘The follow-up email contained a WeTransfer link to a password-gated HTML attachment.’)
  • [T1027 ] Obfuscated Files or Information – The HTML lure used junk padding, comment injection, and encrypted redirect data to evade scanning and classification. (‘junk padding’, ‘HTML comments injected between individual characters’, ‘the actual payload … is never present in plaintext’)
  • [T1102 ] Web Service – The campaign used Salesforce contact forms and WeTransfer as delivery and engagement infrastructure. (‘submitted a seemingly innocuous inquiry through Salesforce’, ‘contained a WeTransfer link’)
  • [T1090 ] Proxy – The phishing flow activated residential/rotating proxies to align attacker traffic with victim geography. (‘activate a proxy through FlashProxy[.]io, a residential/rotating proxy provider’)
  • [T1056.001 ] Input Capture: Keylogging – The lure captured the user-entered device code via a Microsoft sign-in flow that the victim completed on the attacker’s behalf. (‘prompted the victim to enter an attacker-supplied user code’)
  • [T1078 ] Valid Accounts – The attackers used stolen authentication tokens and a Primary Refresh Token to access Microsoft resources as the victim. (‘obtain authentication tokens’, ‘The attacker obtained a Primary Refresh Token (PRT)’)
  • [T1136.001 ] Create Account: Local Account – Not mentioned.
  • [T1136 ] Create Account – The actors registered multiple devices under the stolen token to strengthen persistence. (‘They then registered several devices’)
  • [T1098 ] Account Manipulation – The campaign modified account/device trust by enrolling devices and extending access via token abuse. (‘acquired long-living tokens’, ‘Intune enrollment’)
  • [T1021.004 ] Remote Services: SSH – Not mentioned.
  • [T1199 ] Trusted Relationship – The lure abused legitimate Microsoft and Cloudflare pages to gain victim trust. (‘directed to Microsoft’s legitimate sign-in page’, ‘served by legitimate Cloudflare infrastructure’)
  • [T1057 ] Process Discovery – Not mentioned.
  • [T1119 ] Automated Collection – The attackers harvested emails after obtaining persistent access. (‘harvested emails’)

Indicators of Compromise

  • [Domains ] impersonation and relay infrastructure – bjssourcing[.]com, chartered.flipbookonlinevault[.]com, account-access-rc3uenqi.elitechiropracticandrehab[.]com, and 2 more domains
  • [Email addresses ] disposable registration and persona accounts – jeremyarcher@voewo[.]com, and other voewo[.]com-based personas
  • [File names ] HTML lure and decoy content – 3arhCt9c0p.html, and the decoy NDA PDF
  • [IP addresses ] attacker/proxy activity observed during token abuse – 82.33.39[.]74, 5.230.71[.]51, and other 7 IPs
  • [Device IDs ] attacker-enrolled Windows/Azure AD devices – 4e537622-2514-48b8-84ed-0139549cfab0, 6c290bcc-62d3-40bd-a774-816109af6729, and 5e83a216-f67e-43b8-a129-f67666a001dd
  • [Microsoft App ID ] OAuth client used for device code requests – 29d9ed98-a469-4536-ade2-f981bc1d605e
  • [User agents ] post-compromise automation and filtering – python-requests/2.34.2, Microsoft Office/16.0 (Windows NT 10.0; Microsoft Outlook 16.0.17425; Pro
  • [URLs/paths ] phishing and relay endpoints – /api/harvester?action=geoip, /api/harvester?action=get_code, /turnstile?return_url=…, and /api/harvester?action=poll
  • [User codes ] device code phishing values injected into the lure – CHGNHX34Z


Read more: https://www.esentire.com/blog/ghostcode-dissecting-a-novel-device-code-phishing-kit