Microsoft 365 Phishing Alert: How Attackers Bypass MFA with Evilginx & Device Code Flow (2026)

In the ever-evolving landscape of cybersecurity, the recent revelation of a misconfigured server has exposed a disturbing trend: the proliferation of Evilginx phishing operations targeting Microsoft 365. This incident, uncovered by French security firm Lexfo, sheds light on the intricate web of cyber threats that organizations face in the digital realm. What makes this case particularly intriguing is the sheer audacity of the attackers and the ease with which they were able to exploit vulnerabilities, leaving a trail of compromised accounts and sensitive data in their wake.

The story begins with a simple yet critical oversight: a Python web server left running on a public port with directory listing enabled. This seemingly minor mistake provided a window into the attacker's toolkit, revealing a trove of malicious tools and techniques. From there, Lexfo's researchers were able to pivot and uncover two additional phishing operators, bringing the total to three distinct campaigns.

What makes these campaigns particularly insidious is the attackers' ability to bypass multi-factor authentication (MFA) in two distinct ways. One method involves proxying the live login, while the other abuses a legitimate Microsoft sign-in flow. This highlights the importance of understanding the nuances of these attack vectors and implementing appropriate defenses.

The misconfigured server played a pivotal role in exposing the attackers' activities. The directory listing revealed a wealth of sensitive information, including phishing configurations, credential-harvesting logs, RMM installers, combolists, backup archives, and even the operator's own Telegram session files. This treasure trove of data provided a comprehensive insight into the attackers' operations and their methods.

One of the most striking aspects of this case is the use of Evilginx, an adversary-in-the-middle proxy, in conjunction with a SimpleHelp remote console. The server, located in Budapest, served as a hub for these malicious activities, showcasing the attackers' sophistication and resourcefulness.

The attackers, tracked by Lexfo as codemado, have been active in VoIP and hacking forums since 2018. Their campaign, which began on April 20, continued until at least April 30, with fresh subdomains and renewed wildcard certificates emerging weeks later. The attackers' persistence and ability to adapt are evident in the repeated captures of the same corporate Microsoft 365 accounts from different IP addresses, indicating a methodical approach to their activities.

What's more, the attackers did not build the frameworks they used. Instead, they cloned them from public GitHub repositories, showcasing the ease with which malicious actors can access and exploit existing code. The server held four Evilginx variants, each with its own unique modifications, highlighting the diversity of techniques employed by these attackers.

One of the most intriguing aspects of this case is the use of AI-assisted development. The researchers identified signs of AI involvement across all three operations, with varying degrees of sophistication. The use of AI in phishing campaigns is a concerning trend, as it enables attackers to rapidly adapt and evolve their techniques.

From a defensive perspective, the implications of this case are far-reaching. The two techniques employed by the attackers do not share a common fix. While phishing-resistant MFA, FIDO2, or passkeys can mitigate the Evilginx side of the attack, they do not address the device code abuse. The solution lies in Conditional Access policies, which can effectively block the second path around MFA.

In conclusion, this case serves as a stark reminder of the ever-present threat of phishing operations and the importance of staying vigilant in the face of evolving cyber threats. As the barrier to entry for launching such campaigns continues to decline, organizations must remain proactive in their defense strategies and adapt to the changing landscape of cybersecurity.

Microsoft 365 Phishing Alert: How Attackers Bypass MFA with Evilginx & Device Code Flow (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Nathanael Baumbach

Last Updated:

Views: 6292

Rating: 4.4 / 5 (55 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Nathanael Baumbach

Birthday: 1998-12-02

Address: Apt. 829 751 Glover View, West Orlando, IN 22436

Phone: +901025288581

Job: Internal IT Coordinator

Hobby: Gunsmithing, Motor sports, Flying, Skiing, Hooping, Lego building, Ice skating

Introduction: My name is Nathanael Baumbach, I am a fantastic, nice, victorious, brave, healthy, cute, glorious person who loves writing and wants to share my knowledge and understanding with you.