GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation

A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are revoked. GhostCode begins with business-email social engineering rather than a conventional credential-harvesting page. Operators impersonated procurement staff from legitimate organizations, including BJ’s Wholesale Club, and submitted benign inquiries through Salesforce contact forms. Once a sales […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: