Barracuda Device Code Phishing Report exposes new attack model

DQChannels Bureau
DQChannels Bureau
Barracuda Device Code Phishing Report exposes new attack model

The Barracuda Device Code Phishing Report highlights a shift that feels subtle but is deeply concerning. Attackers are no longer relying on fake websites or stolen passwords. Instead, they are using legitimate login flows to trick users into granting access themselves. This changes the entire nature of phishing, making it harder to detect and even harder to stop.

At the centre of this is the misuse of OAuth 2.0 device code flow security, a feature originally designed for convenience. It allows users to sign in on one device by entering a code on another. But this same simplicity is now being exploited, turning a trusted process into a security gap.

How attackers bypass MFA with device code phishing

One of the most striking findings is how attackers can bypass MFA with device code phishing. Unlike traditional phishing, there is no fake login page or suspicious link. Victims are directed to real authentication portals, where they unknowingly approve access for the attacker’s device.

Once the code is entered, the system issues valid access and refresh tokens. This gives attackers persistent access without needing passwords. Even if the user resets their credentials later, the session can continue. This makes the attack both stealthy and long-lasting, especially in environments like Microsoft 365 and Entra ID.

Industrial scale attacks powered by EvilTokens phishing kit

The scale of this threat is growing rapidly. The report points to the rise of phishing-as-a-service tools like the EvilTokens phishing kit Microsoft 365, which are making these attacks easier to deploy. In just four weeks, Barracuda detected 7 million such attacks, indicating how quickly this method is being adopted.

This industrialisation means attackers no longer need deep technical skills. With ready-made tools, they can launch campaigns that look legitimate and operate at scale. The result is a surge in attacks that blend into normal user activity.

Why traditional defences are falling behind

Traditional security measures struggle in this scenario because the attack does not break the rules, it follows them. Since users willingly enter the code, security systems see the activity as authorised. This limits the effectiveness of common protections, including Conditional Access policies for device codes, which may not always flag such behaviour.

The attack also avoids typical warning signs. There are no suspicious domains or obvious phishing indicators. Instead, it relies on user trust and familiarity with entering short codes, making it harder for both systems and people to spot.

Trust becomes the new attack surface

The Barracuda Device Code Phishing Report makes one thing clear. The battleground is shifting from credentials to behaviour. Attackers are now exploiting trust rather than vulnerabilities, using legitimate systems to gain access.

For organisations, this means rethinking security beyond detection. The focus needs to move towards visibility, control over authentication flows, and continuous monitoring. In a world where users can unknowingly grant access, the challenge is no longer just blocking threats, but understanding them in real time.

Read More: 

Latest Stories