Tradecraft Tuesday | We Need to Talk About Device Code Phishing

Tradecraft Tuesday | We Need to Talk About Device Code Phishing

Source: YouTube · Huntress · published Jun 10, 2026 · 1:01:13

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Huntress researchers Jenko Wong and Dave Clantland demonstrate how device code phishing exploits OAuth to steal Microsoft tokens, escalate privileges, and achieve persistent access 0:29.

Key Takeaways:
• Device code flow, designed for devices without keyboards like smart TVs, can be weaponized when attackers impersonate legitimate Microsoft apps to trick users into authenticating on real Microsoft pages 8:15.
• Attackers can exchange an Outlook token for Azure management tokens through Microsoft's "family of client IDs" feature, enabling lateral movement to broader resources without additional user consent 17:30.
• Advanced attacks hijack device registration services to obtain Primary Refresh Tokens and Windows Hello for Business keys, providing near-permanent access that's difficult to detect and revoke 22:00.
• The Evil Tokens campaign demonstrated large-scale device code phishing using compromised websites, Railway proxies, and Cloudflare workers to evade traditional security controls 28:00.
• Defenses include conditional access policies to block device code flow, monitoring for suspicious new device registrations, and analyzing logs for anomalous token exchanges across resources 40:00.

Device code phishing represents a sophisticated abuse of OAuth protocols where attackers bypass traditional phishing indicators by directing users to legitimate authentication pages, making this attack particularly challenging to detect and prevent through user training alone.

Sources:

  • 0:29 Introduction to device code fishing topic
  • 8:15 OAuth

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[music] [music] [music] All right, welcome everyone. Hello out there. Welcome to Trade Craft Tuesday. This week we're going to talk about device code fishing. And it's a matter of opinion whether you think it's a scorge or plague. That didn't quite get by marketing with the original title, but we hope to take you on a fun little journey. I want to just introduce who will be speaking with you today. I'm Jenko Wong. I'm a principal product researcher at Huntress. And just to turn it over to my partner Dave, want you want to introduce yourself quickly? >> Yeah. Dave Clantland, also principal product researcher here at Huntress, focusing pretty heavily on the Microsoft identity side of things. >> Yeah. And you know, a lot of what we spend our time on is identity abuse. And what better sort of …