# The MFA Killer That Nobody Saw Coming — And Now Can't Be Stopped
Your hardware security key doesn't help. Your passkey doesn't help. Your authenticator app doesn't help. Device code phishing doesn't care about any of them — and it's now generating 7 million attacks in a single four-week stretch.
By April 2026, Microsoft was logging 10 to 15 entirely new device code phishing campaigns every 24 hours. The FBI had issued a standalone advisory naming a specific phishing-as-a-service kit — Kali365 — a level of specificity that federal agencies almost never bother with. Push Security, which added device code phishing to its Browser & Identity Attacks Matrix back in 2023 when almost nobody was paying attention, now tracks more than 25 distinct kits operating in the wild. Three years ago this was a red-team curiosity. Today it's a commodity product with paying subscribers.
Here's what makes the velocity unusual: AiTM phishing, the last major credential-theft evolution, took years to move from research paper to nation-state tool to criminal PhaaS offering. Device code phishing completed that entire arc in months.
## Why Your MFA Controls Are Irrelevant Here
The attack exploits a structural gap in how OAuth 2.0 was designed — and that gap isn't going away with a patch.
The device authorization flow was built for input-constrained hardware: smart TVs, printers, IoT devices that can't render a full browser login. The idea is simple — display a short code on screen, the user types it into a separate device at login.microsoftonline.com/common/oauth2/deviceauth, authenticates there, and the original device gets a token. Legitimate. Intentional. Widely adopted well beyond its original scope, including CLI tools that millions of developers use daily.
The attack exploits exactly this flow. The victim receives a phishing message, visits what looks like a routine login page, copies a code, navigates to the *actual legitimate Microsoft URL*, authenticates with their real credentials and real MFA, picks their account from a dropdown, clicks Allow. That's it. That's the entire attack.
The attacker gets a refresh token. The victim's authentication was flawless — because it was. The problem is that authentication and authorization are two different things in OAuth, and most enterprise security controls only harden the first. Passkeys prove identity. Hardware security keys prove identity. None of that governs what an application is then permitted to access on your behalf.
## From Nation-State Technique to $50/Month Subscription
The commercialization timeline is worth understanding in detail because it explains why the threat surface exploded so fast.
Researchers documented the attack vector in 2020. For four years it remained a niche concern, mostly theoretical. In 2024, Storm-2372 — a threat actor attributed to Russian intelligence services — started using it operationally against high-value targets. In 2025, ShinyHunters ran device code phishing campaigns against Salesforce tenants at scale. Then in February 2026, the EvilTokens kit arrived and the criminal market caught fire.
The EvilTokens release is significant not just because of what it did, but because of what it enabled. Once a capable, well-documented kit exists, it becomes a blueprint. LLM-assisted development means a motivated operator can fork, customize, and ship a new kit in days. Push Security's researchers noted that independently-built kits using similar AI-generated scaffolding can look structurally identical — which complicates attribution and makes it harder to say with confidence that apparent "forks" represent a single threat actor rather than parallel development.
The current generation of kits isn't just running basic token theft. ARToken ships with Primary Refresh Token persistence, automated mailbox access, BEC automation, and SharePoint exfiltration bundled as product features. Tycoon2FA — previously the most common AiTM kit in the wild — added device code phishing to its framework in May. Kali365 offers both techniques in a single platform. This is a mature market.
## The 15-Minute Token Window Problem
One detail that's not getting enough attention: the device code flow has a built-in 15-minute window during which the code is valid and polling continues. Attackers don't need the victim to act immediately — they can send the phishing lure, wait, and the token poll keeps running in the background. If the victim clicks through during a busy moment, authenticates quickly, and moves on, the attacker has a fully valid session without the victim ever registering that something was wrong.
Unlike credential phishing, there's no password typed into a suspicious form. Unlike AiTM, there's no proxy in the middle of the session. The victim interacts only with legitimate Microsoft infrastructure. Behavioral detection looking for anomalous login patterns may see nothing at all on the authentication side — because the authentication was clean.
## What Defenders Can Actually Do
Conditional Access policies with device code flow restrictions are the most direct mitigation for Microsoft environments. Azure AD allows organizations to block or restrict the device authorization grant for applications where it isn't necessary — which, for most enterprise users, is most of them. If your workforce doesn't authenticate CLI tools against your Microsoft tenant, there's no reason to leave that flow open.
Beyond that, the focus has to shift toward post-authentication signal: anomalous application consents, unexpected token usage from unusual IP ranges, and applications that a user has never authorized before suddenly appearing with refresh tokens. That's where the attack leaves its fingerprints.
The broader lesson is harder to implement: identity security controls need to cover the authorization layer, not just the authentication layer. Most enterprise security programs haven't caught up to that distinction yet.
---
## HackWire Analysis
Device code phishing represents something more significant than another phishing variant getting weaponized — it's a proof of concept that the MFA era of identity security has a structural ceiling, and we're watching attackers find it in real time.
The framing of "MFA bypass" is technically accurate but slightly misleading in a way that matters for defenders. This isn't a bypass in the sense of defeating a control — it's an exploitation of a seam between two controls that were never designed to overlap. Authentication proves identity. Authorization grants access. Enterprise security has spent a decade hardening the first and left the second largely exposed. Device code phishing is the tax on that omission.
The commercialization speed is genuinely alarming. AiTM phishing took roughly four years from first credible criminal adoption to widespread PhaaS availability. Device code phishing did it in under two. The accelerant is obvious: LLM-assisted kit development lowers the skill floor, documented attack techniques spread faster through criminal ecosystems, and an established PhaaS market provides instant distribution infrastructure. The next novel OAuth flow attack — and there will be one — could complete the same cycle in weeks.
What other reporting is largely missing: the downstream impact on BEC. Device code phishing doesn't just steal credentials, it hands attackers persistent mailbox access. ARToken's built-in BEC automation means a successful token harvest can translate directly into wire fraud campaigns, invoice hijacking, or executive impersonation — all without triggering a credential reset because no password was ever compromised. Finance and legal teams at organizations that consider themselves "past" basic BEC risk because they have MFA everywhere should reconsider that assumption immediately.
The organizations most exposed right now are those running hybrid Microsoft environments where conditional access policies haven't been audited since before this wave began — which, based on incident patterns from the first half of 2026, is most of them.
— HackWire Editorial
---
## Related Coverage