Episode Details

Back to Episodes

GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds

Season 1 Episode 112 Published 2 weeks ago
Description

Daily Cyber News: GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds

A Microsoft 365 account can be taken over even when the victim completes authentication, including multifactor authentication, on a legitimate Microsoft page. The GhostCode phishing kit does this by persuading a user to approve a device-code sign-in that is actually linked to the attacker. In one observed intrusion, the attackers made nine successful A P I calls, registered three devices in 78 seconds, and obtained a Primary Refresh Token in 32 seconds.

Key context: This approach can defeat familiar password-theft warnings because the user sees Microsoft’s real sign-in experience.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, phishing, microsoft 365, GhostCode, hijack, Microsoft, accounts, little.

Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us