GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds
Daily Cyber News: GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds
A Microsoft 365 account can be taken over even when the victim completes authentication, including multifactor authentication, on a legitimate Microsoft page. The GhostCode phishing kit does this by persuading a user to approve a device-code sign-in that is actually linked to the attacker. In one observed intrusion, the attackers made nine successful A P I calls, registered three devices in 78 seconds, and obtained a Primary Refresh Token in 32 seconds.
Key context: This approach can defeat familiar password-theft warnings because the user sees Microsoft’s real sign-in experience.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, phishing, microsoft 365, GhostCode, hijack, Microsoft, accounts, little.