Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Scams & Fraud

Microsoft Reveals AI Phishing Campaign Hitting Hundreds of ORGS Daily

Microsoft uncovers an advanced AI-driven phishing campaign abusing OAuth device code authentication to bypass MFA, automate attacks, and steal access tokens from Microsoft 365 accounts

Saravana Kumar Mahendran by Saravana Kumar Mahendran
April 8, 2026
in Scams & Fraud
0 0
Microsoft Reveals AI Phishing Campaign

Designed By Freepik

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Microsoft Defender Security Research has exposed a sophisticated AI-enabled phishing campaign that abuses the OAuth Device Code Authentication flow to steal access and refresh tokens from Microsoft 365 accounts. Threat actors employ generative AI for hyper-personalized lures and full end-to-end automation, bypassing traditional MFA and the standard 15-minute device code expiration through dynamic, on-demand code generation. The operation, powered by the EvilTokens Phishing-as-a-Service toolkit, has compromised hundreds of organizations daily since mid-March 2026, marking a major escalation from earlier manual campaigns.

AI-Driven Attack Chain

Reconnaissance begins 10 to 15 days prior, with actors querying Microsoft’s GetCredentialType API to validate active email addresses in target tenants. Phishing emails, crafted with generative AI for role-specific relevance, use themes such as RFPs, invoices, document sharing, electronic signatures, or voicemail notifications. Victims clicking links encounter multi-stage redirects via compromised legitimate domains and serverless platforms like Vercel, Cloudflare Workers, AWS Lambda, and Railway.com to evade scanners.

On the final landing page, often mimicking a browser-in-the-browser or blurred document preview with a “Verify identity” prompt, a background script sends a real-time POST request to the attackers’ backend. This triggers live device code generation via Microsoft’s official endpoint, displayed alongside an auto-copied code using the JavaScript clipboard API and a redirect button to microsoft.com/devicelogin. A hidden polling mechanism checks status every 3 to 5 seconds using a session identifier, capturing valid tokens immediately upon user authentication on the legitimate site. This dynamic approach ensures the full 15-minute validity window starts only at victim interaction, significantly boosting success rates over static methods.

Escalation from Prior Campaigns

The current activity builds on Storm-2372’s device code phishing observed in February 2025, which relied on manual social engineering via messaging apps and Teams invitations targeting government, defense, and critical infrastructure sectors. In contrast, the 2026 campaign shifts to industrialized automation and AI integration across reconnaissance, lure generation, infrastructure spinning with thousands of short-lived polling nodes on Railway.com, and exploitation. Microsoft links this surge to the emergence of EvilTokens PhaaS in early 2026, enabling criminal actors to scale operations far beyond nation-state efforts like Storm-2372.

Broader threat actor abuse of AI, detailed in a related April 2 Microsoft report, shows generative tools accelerating every attack phase, including 450 percent higher phishing click-through rates via localized messaging and automated payload refinement, while transforming AI systems themselves into new attack surfaces. The device code campaign exemplifies this evolution from AI as a tool to a core enabler of resilient, high-volume credential theft.

Critical Campaign Details

Reconnaissance via GetCredentialType API occurs 10 to 15 days before phishing, followed by 10 to 15 distinct AI-personalized campaigns launching daily since March 15, 2026.
Dynamic device code generation at the final landing page, combined with 3 to 5 second polling and auto-clipboard functionality, circumvents the 15-minute expiration.
Infrastructure heavily abuses serverless platforms such as Vercel, Cloudflare Workers, AWS Lambda, and Railway.com along with compromised domains for redirects and backend operations.
Post-compromise activity focuses on high-value financial and executive personas via Microsoft Graph reconnaissance, new device registration for Primary Refresh Tokens often within 10 minutes, malicious inbox rules, and targeted email exfiltration of wire transfers and invoices.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: Crypto Scams
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Delio’s CEO Was Convicted of a Third of What He Was Charged With
Scams & Fraud

Delio’s CEO Was Convicted of a Third of What He Was Charged With

by Saravana Kumar Mahendran
August 13, 2026

Seoul's Southern District Court sentenced Delio founder and CEO Jeong Sang-ho to 15 years in prison on August 13, ordering...

Read moreDetails
Arizona’s Crypto ATM Refunds Total $171,332 for 35 Victims, Against a $177M Problem

Arizona’s Crypto ATM Refunds Total $171,332 for 35 Victims, Against a $177M Problem

August 13, 2026
Hawaii Bans Cash-to-Crypto ATM Deposits Starting October 1

Hawaii Crypto ATM Ban Exposes a Liquidity Gap

August 13, 2026
New CFTC Complaint Shows Goliath Ventures Paid Recruiters Twice What It Paid Victims

New CFTC Complaint Shows Goliath Ventures Paid Recruiters Twice What It Paid Victims

August 12, 2026
Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

August 8, 2026
Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

August 8, 2026
oung people from the Russian regions looking for easy money

FSB Shuts Down Nine Illegal Moscow Crypto Exchanges Linked to Ukrainian Call-Center Fraud

August 8, 2026
Next Post
Anthropic Launches Project Glasswing to Test AI Cybersecurity Model Claude Mythos Preview

Claude Mythos Exposes Hidden Zero-Days: What It Means for Crypto

SOL Strategies Acquires Darklake Labs for $1.2 Million to Integrate Zero-Knowledge Privacy Technology on Solana

SOL Strategies Acquires Darklake Labs for $1.2 Million to Integrate Zero-Knowledge Privacy Technology on Solana

Recommended

  • All
  • Crypto News Today
Binance to Halt Transactions With 11 Crypto Platforms Aug. 23

Binance to Halt Transactions With 11 Crypto Platforms Aug. 23

August 14, 2026
Upbit and Bithumb to Delist STORJ, JASMY and TT After Warning Reviews

Upbit and Bithumb to Delist STORJ, JASMY and TT After Warning Reviews

August 14, 2026
Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

Trezor’s Third Vendor Breach in Four Years Lands Amid a Wider Logistics Data-Leak Wave

August 14, 2026
JPMorgan Closed Polymarket Account While Pursuing Its IPO

JPMorgan Closed Polymarket Account While Pursuing Its IPO

August 14, 2026
Baltimore’s Kalshi Case Rests on a Warning Letter With Casino-Lobby Roots

Baltimore’s Kalshi Case Rests on a Warning Letter With Casino-Lobby Roots

August 14, 2026
Tether Completes First Big Four Audit, Reporting $6.8B Reserve Surplus

Tether Completes First Big Four Audit, Reporting $6.8B Reserve Surplus

August 14, 2026
MSCI Proposal Puts Strategy and Metaplanet at Risk of Index Removal

MSCI Proposal Puts Strategy and Metaplanet at Risk of Index Removal

August 14, 2026
BitGo Q2 2026: Revenue Jumps 80% as Margins Narrow

BitGo Q2 2026: Revenue Jumps 80% as Margins Narrow

August 13, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • SEC Regulation Crypto vs. CLARITY Act: Two Paths for Crypto Rules
  • Binance to Halt Transactions With 11 Crypto Platforms Aug. 23
  • Upbit and Bithumb to Delist STORJ, JASMY and TT After Warning Reviews

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.