{"success":true,"data":{"id":"eviltokens-device-code","label":"OAuth device code flow phishing — attacker sends XXXX-XXXX code and directs victim to devicelogin URL","description":"OAuth Device Code Flow phishing (EvilTokens variant) — attacker sends a device authorization code (XXXX-XXXX) and directs victim to a legitimate device-auth URL (microsoft.com/devicelogin, github.com/login/device) to enter it. Once the victim authorizes, the attacker receives a full OAuth access token, completely bypassing FIDO2/hardware token 2FA since authentication occurs at a genuine Microsoft/GitHub URL. Surge documented in Entra ID / Azure AD tenant targeting 2025-2026. The signal fires when: (1) a device code pattern (XXXX-XXXX alphanumeric) is present AND (2) a device-auth URL is present AND (3) device-code framing context (\"enter the code\", \"device authorization\") is present AND (4) sender is NOT from microsoft.com, github.com, google.com, or slack.com. Source: GC1 R13 council #1; Secureworks CTU-MA-20230601; Microsoft MSRC device-code advisory 2025.","tier":"warning","category":"other","isThin":false}}