GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds

GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds. A Microsoft 365 account can be taken over even when the victim completes authentication, including multifactor authentication, on a legitimate Microsoft page.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 18th, 2026.

A Microsoft 365 account can be taken over even when the victim completes authentication, including multifactor authentication, on a legitimate Microsoft page. The GhostCode phishing kit does this by persuading a user to approve a device-code sign-in that is actually linked to the attacker. In one observed intrusion, the attackers made nine successful A P I calls, registered three devices in 78 seconds, and obtained a Primary Refresh Token in 32 seconds. The campaign began with business contact forms, used a request to sign an NDA, and delivered a password-protected HTML attachment.

This approach can defeat familiar password-theft warnings because the user sees Microsoft’s real sign-in experience. It also creates a recovery challenge because registered devices may preserve access after a stolen token is revoked. Leaders should allow device-code authentication only where a defined business process genuinely requires it. Defenders should monitor device registrations, device-code events, scripted A P I activity, and suspicious non-interactive sessions. Block device-code authentication by default, and investigate newly registered devices whenever suspicious sign-in activity appears. The wider pattern is clear: attackers increasingly focus on stealing authorization rather than stealing passwords.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds
Broadcast by