Decoding the world of cybersecurity

· ·

Device-code phishing targets European Microsoft 365 users

A phishing operation targeting organisations in Europe and the US is abusing Microsoft 365 device-code authentication before deploying legitimate remote-management software on compromised endpoints.

Device-code phishing targets European Microsoft 365 users
Summary
  • Gurucul says the CSuite campaign targets organisations in Europe and the US with document, collaboration, and voicemail lures.
  • The campaign abuses device-code authentication to hijack Microsoft 365 sessions before deploying legitimate remote-management tools.
  • The activity shows how cloud identity and endpoint administration can be combined in the same intrusion without exploiting Microsoft software.

A phishing operation targeting organisations in Europe and the United States is abusing Microsoft 365 device-code authentication to hijack sessions before moving further into victim environments with legitimate remote-management software.

Gurucul, which calls the operation CSuite, says attackers are using lures impersonating familiar business services including Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365 voicemail. Sixty per cent of the victims identified in its research were based in the US, with the remaining activity including European organisations.

The campaign combines conventional social engineering with an authentication flow intended for legitimate use. Device-code authentication allows a user to authorise an application by entering a code on another device or browser. The mechanism is useful where the original device has limited input capabilities, but it can be abused when an attacker convinces a victim to complete authentication on the attacker’s behalf.

The victim can still interact with a legitimate Microsoft authentication service, making the sequence different from a traditional fake sign-in page. Once the user authorises the session, the attacker can obtain access associated with the resulting token rather than depending solely on a reusable password.

Gurucul says CSuite uses that mechanism to hijack Microsoft 365 sessions and subsequently deploy legitimate remote-management products including ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.

Those tools have ordinary administrative purposes, but the same functions can provide remote access and execution after an account or endpoint has been compromised. Their use can make detection harder where an organisation already permits remote support or management software as part of routine operations.

The campaign consequently crosses two control planes that are often managed separately: cloud identity and endpoint administration. A successful authentication event can look valid at the identity layer, while a recognised management tool can appear legitimate on the endpoint. The malicious context emerges from the sequence and ownership of those events rather than either technology being inherently hostile.

That distinction has become more important as businesses place email, files, collaboration tools, and applications behind cloud identity. Multi-factor authentication remains a substantial barrier to account takeover, but some phishing techniques are designed to manipulate users into authorising an attacker’s session instead of stealing the second factor directly.

Remote-management software presents a related governance problem. Products used by internal IT teams, outsourced support providers, and managed service companies often require substantial privileges. Organisations that permit several such platforms can find it difficult to distinguish an expected deployment from an attacker introducing another legitimate agent after gaining access.

Gurucul has published infrastructure indicators associated with the campaign, but the research does not establish the complete number of affected European organisations or identify all victims. Its findings should therefore be treated as analysis of an observed campaign rather than a measure of the overall prevalence of device-code phishing.

The activity nevertheless illustrates why authentication assurance increasingly depends on the full context of a session — the application requesting access, the device involved, the user’s expected behaviour, and what happens immediately after authorisation — rather than whether a valid MFA event simply appears in a log.

As cloud identities become gateways to multiple enterprise services, attackers have a growing incentive to target the mechanics of session authorisation itself.

×