
Tradecraft Tuesday | We Need to Talk About Device Code Phishing
Source: YouTube · Huntress · published Jun 10, 2026 · 1:01:13
Huntress researchers Jenko Wong and Dave Clantland demonstrate how device code phishing exploits OAuth to steal Microsoft tokens, escalate privileges, and achieve persistent access 0:29.
Key Takeaways:
• Device code flow, designed for devices without keyboards like smart TVs, can be weaponized when attackers impersonate legitimate Microsoft apps to trick users into authenticating on real Microsoft pages 8:15.
• Attackers can exchange an Outlook token for Azure management tokens through Microsoft's "family of client IDs" feature, enabling lateral movement to broader resources without additional user consent 17:30.
• Advanced attacks hijack device registration services to obtain Primary Refresh Tokens and Windows Hello for Business keys, providing near-permanent access that's difficult to detect and revoke 22:00.
• The Evil Tokens campaign demonstrated large-scale device code phishing using compromised websites, Railway proxies, and Cloudflare workers to evade traditional security controls 28:00.
• Defenses include conditional access policies to block device code flow, monitoring for suspicious new device registrations, and analyzing logs for anomalous token exchanges across resources 40:00.
Device code phishing represents a sophisticated abuse of OAuth protocols where attackers bypass traditional phishing indicators by directing users to legitimate authentication pages, making this attack particularly challenging to detect and prevent through user training alone.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] [music] [music] All right, welcome everyone. Hello out there. Welcome to Trade Craft Tuesday. This week we're going to talk about device code fishing. And it's a matter of opinion whether you think it's a scorge or plague. That didn't quite get by marketing with the original title, but we hope to take you on a fun little journey. I want to just introduce who will be speaking with you today. I'm Jenko Wong. I'm a principal product researcher at Huntress. And just to turn it over to my partner Dave, want you want to introduce yourself quickly? >> Yeah. Dave Clantland, also principal product researcher here at Huntress, focusing pretty heavily on the Microsoft identity side of things. >> Yeah. And you know, a lot of what we spend our time on is identity abuse. And what better sort of …