Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Scams & Fraud

Microsoft Reveals AI Phishing Campaign Hitting Hundreds of ORGS Daily

Microsoft uncovers an advanced AI-driven phishing campaign abusing OAuth device code authentication to bypass MFA, automate attacks, and steal access tokens from Microsoft 365 accounts

Saravana Kumar Mahendran by Saravana Kumar Mahendran
April 8, 2026
in Scams & Fraud
0 0
Microsoft Reveals AI Phishing Campaign

Designed By Freepik

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Microsoft Defender Security Research has exposed a sophisticated AI-enabled phishing campaign that abuses the OAuth Device Code Authentication flow to steal access and refresh tokens from Microsoft 365 accounts. Threat actors employ generative AI for hyper-personalized lures and full end-to-end automation, bypassing traditional MFA and the standard 15-minute device code expiration through dynamic, on-demand code generation. The operation, powered by the EvilTokens Phishing-as-a-Service toolkit, has compromised hundreds of organizations daily since mid-March 2026, marking a major escalation from earlier manual campaigns.

AI-Driven Attack Chain

Reconnaissance begins 10 to 15 days prior, with actors querying Microsoft’s GetCredentialType API to validate active email addresses in target tenants. Phishing emails, crafted with generative AI for role-specific relevance, use themes such as RFPs, invoices, document sharing, electronic signatures, or voicemail notifications. Victims clicking links encounter multi-stage redirects via compromised legitimate domains and serverless platforms like Vercel, Cloudflare Workers, AWS Lambda, and Railway.com to evade scanners.

On the final landing page, often mimicking a browser-in-the-browser or blurred document preview with a “Verify identity” prompt, a background script sends a real-time POST request to the attackers’ backend. This triggers live device code generation via Microsoft’s official endpoint, displayed alongside an auto-copied code using the JavaScript clipboard API and a redirect button to microsoft.com/devicelogin. A hidden polling mechanism checks status every 3 to 5 seconds using a session identifier, capturing valid tokens immediately upon user authentication on the legitimate site. This dynamic approach ensures the full 15-minute validity window starts only at victim interaction, significantly boosting success rates over static methods.

Escalation from Prior Campaigns

The current activity builds on Storm-2372’s device code phishing observed in February 2025, which relied on manual social engineering via messaging apps and Teams invitations targeting government, defense, and critical infrastructure sectors. In contrast, the 2026 campaign shifts to industrialized automation and AI integration across reconnaissance, lure generation, infrastructure spinning with thousands of short-lived polling nodes on Railway.com, and exploitation. Microsoft links this surge to the emergence of EvilTokens PhaaS in early 2026, enabling criminal actors to scale operations far beyond nation-state efforts like Storm-2372.

Broader threat actor abuse of AI, detailed in a related April 2 Microsoft report, shows generative tools accelerating every attack phase, including 450 percent higher phishing click-through rates via localized messaging and automated payload refinement, while transforming AI systems themselves into new attack surfaces. The device code campaign exemplifies this evolution from AI as a tool to a core enabler of resilient, high-volume credential theft.

Critical Campaign Details

Reconnaissance via GetCredentialType API occurs 10 to 15 days before phishing, followed by 10 to 15 distinct AI-personalized campaigns launching daily since March 15, 2026.
Dynamic device code generation at the final landing page, combined with 3 to 5 second polling and auto-clipboard functionality, circumvents the 15-minute expiration.
Infrastructure heavily abuses serverless platforms such as Vercel, Cloudflare Workers, AWS Lambda, and Railway.com along with compromised domains for redirects and backend operations.
Post-compromise activity focuses on high-value financial and executive personas via Microsoft Graph reconnaissance, new device registration for Primary Refresh Tokens often within 10 minutes, malicious inbox rules, and targeted email exfiltration of wire transfers and invoices.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: Crypto Scams
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Trump-Linked GOLD Token Crashes 99% Days After Eric Trump Denied Any New Coin
Market Updates

Trump-Linked GOLD Token Crashes 99% Days After Eric Trump Denied Any New Coin

by Saravana Kumar Mahendran
August 29, 2026

A token called Trump Digital Gold collapsed 99% within hours of its Saturday launch on Solana, after wallets controlling 82.45%...

Read moreDetails
CFTC Warns of Rising Crypto ATM Fraud as Losses Hit $388 Million in 2025

CFTC Warns of Rising Crypto ATM Fraud as Losses Hit $388 Million in 2025

August 27, 2026
Crypto Dust From HTX Wallets

Kraken Froze HTX-Linked Sanctioned Crypto Dust HTX Denies Sending It.

August 26, 2026
Las Vegas man convicted in $24M crypto Ponzi scheme, his second SEC case

Las Vegas man convicted in $24M crypto Ponzi scheme, his second SEC case

August 25, 2026
Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

Kylie Jenner’s X Account Hacked to Push a Pump.fun Token

August 25, 2026
Zimbardi Deported From Fiji and Indicted in the U.S. After Three Years of Regulatory Warnings

Zimbardi Deported From Fiji and Indicted in the U.S. After Three Years of Regulatory Warnings

August 18, 2026
Delio’s CEO Was Convicted of a Third of What He Was Charged With

Delio’s CEO Was Convicted of a Third of What He Was Charged With

August 13, 2026
Next Post
SOL Strategies Acquires Darklake Labs for $1.2 Million to Integrate Zero-Knowledge Privacy Technology on Solana

SOL Strategies Acquires Darklake Labs for $1.2 Million to Integrate Zero-Knowledge Privacy Technology on Solana

UBS, PostFinance, Sygnum Launch CHF Stablecoin Sandbox with Swiss Banks

UBS, PostFinance, Sygnum Launch CHF Stablecoin Sandbox with Swiss Banks

Recommended

  • All
  • Crypto News Today
Bitcoin Spot ETFs Pull In $924M Last Week as BlackRock’s IBIT Leads

Bitcoin Spot ETFs Record $924.48M, Ethereum ETFs Add $824.42M in Net Inflows

August 31, 2026

Metaplanet Transfers 3,200 BTC Worth $248.67M to Coinbase Prime

August 31, 2026
Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

August 31, 2026
Trump-Linked GOLD Token Crashes 99% Days After Eric Trump Denied Any New Coin

Trump-Linked GOLD Token Crashes 99% Days After Eric Trump Denied Any New Coin

August 29, 2026
Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

Fogo Foundation Says Wallet Breach Sent 400M FOGO Tokens to Unknown Attacker

August 29, 2026
Bitcoin ETFs Reverse Course With $202M Outflow After Nine-Day Run

Bitcoin ETFs See $202M Outflow, Ending 9-Day Inflow Streak

August 29, 2026
Cardone Capital's 1,200 BTC Buy Blows Past Its Own 2026 Bitcoin Target

Cardone Capital’s 1,200 BTC Buy Blows Past Its Own 2026 Bitcoin Target

August 29, 2026
Kalshi Loses Nevada Appeal, Deepening U.S. Prediction Market Legal Split

Kalshi Loses Nevada Appeal, Deepening U.S. Prediction Market Legal Split

August 29, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days
  • Bitcoin Spot ETFs Record $924.48M, Ethereum ETFs Add $824.42M in Net Inflows
  • Metaplanet Transfers 3,200 BTC Worth $248.67M to Coinbase Prime

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.