GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation
A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are revoked. GhostCode begins with business-email social engineering rather than a conventional credential-harvesting page. Operators impersonated procurement staff from legitimate organizations, including BJβs Wholesale Club, and submitted benign inquiries through Salesforce contact forms. Once a sales [β¦]
The post GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
