GhostCode Phishing Kit Leverages Microsoft Entra Device Enrollment to Bypass Token Revocation
Security researchers have identified a new phishing toolkit, dubbed GhostCode, that exploits Microsoft Entra's device enrollment process to preserve unauthorized access even after compromised authentication tokens are revoked. The technique represents a shift from traditional credential‑stealing attacks, allowing threat actors to maintain a foothold within targeted networks despite standard remediation steps.
Unlike conventional phishing campaigns that direct victims to credential‑harvesting web pages, GhostCode initiates contact through business‑email social engineering. Recipients receive seemingly legitimate messages that prompt them to enroll a device with Microsoft Entra, a cloud identity service that manages access to Microsoft 365 and Azure resources. During the enrollment flow, the kit intercepts the generated device code and uses it to acquire authentication tokens on behalf of the victim.
Microsoft Entra issues short‑lived tokens that grant access to cloud resources, and organizations typically mitigate breaches by revoking these tokens once a compromise is detected. GhostCode circumvents this safeguard by automatically re‑enrolling the compromised device after a revocation event, effectively generating fresh tokens without user interaction. This persistence mechanism enables attackers to continue accessing data and services long after the initial breach is discovered.
The discovery raises concerns for enterprises that rely heavily on Microsoft’s identity platform for remote work and cloud workloads. Because the attack leverages a legitimate enrollment pathway, standard email filters and endpoint detectors may not flag the activity as malicious. Security teams are advised to monitor for anomalous device enrollment requests, enforce multi‑factor authentication for enrollment actions, and implement conditional access policies that limit token issuance to known, trusted devices.
The GhostCode kit was first reported by the independent security community GBHackers, which provided technical details to both the public and Microsoft’s threat‑intelligence teams. Microsoft has acknowledged the report and indicated that it is reviewing the findings to strengthen the enrollment flow against abuse. As investigations continue, organizations are encouraged to apply the latest security updates, review enrollment logs for irregular patterns, and consider additional verification steps for device registration to reduce the risk of this emerging threat.
Comments (0)
Be the first to comment.
Join the discussion