Solid AI Phish campaign writeup with IoCs from Microsoft (Storm-2372)

Posting this here since the writeup from Microsoft is long and detailed and can be found here: Inside an AI‑enabled device code phishing campaign | Microsoft Security Blog

The Detections they give for Sentinel/Defender can be re-written for other SIMs/EDRs. The more interesting item to me is how they paired automation on the backend logic with AI generated phishing lures.

3 Likes

Reclassifying as Threat Intel because it’s actionable, per our criteria.

1 Like

This is a really slick implementation of device code auth. It doesn’t even have the weird context-switching problem of ClickFix, since the DCA is handled entirely in-browser.

1 Like

I have been seeing a TON of device code phishing attacks in the last months. It is almost as common as typical AitM/Cred Harvesting attacks now.