How Hackers Bypass Microsoft 365 MFA: Evilginx & Device Code Phishing Explained (2026)

In today's digital landscape, the threat of phishing attacks is ever-present, and a recent incident has shed light on the sophisticated tactics employed by cybercriminals. This article delves into the story of a misconfigured server that revealed a network of phishing operations, highlighting the importance of staying vigilant and adapting security measures.

The Unveiling of Phishing Operations

A simple mistake by an attacker, leaving a Python web server exposed, led to the discovery of three separate phishing campaigns targeting Microsoft 365 users. This incident, investigated by Lexfo, a French security firm, showcases how a single oversight can unravel an entire operation.

The Operators and Their Tactics

The exposed server belonged to an attacker codenamed codemado, an Egyptian actor active in VoIP and hacking forums since 2018. His campaign, which went live in April 2026, primarily targeted corporate mailboxes, leveraging a custom fork of the open-source Evilginx proxy.

What makes this particularly fascinating is the way these operators adapted their tactics. Two of the campaigns bypassed Multi-Factor Authentication (MFA) in different ways: one by proxying live logins and the other by abusing a legitimate Microsoft sign-in flow. This diversity in attack methods is a clear indicator of the evolving nature of cyber threats.

Unraveling the Toolkit

Lexfo's investigation revealed that codemado did not develop his framework from scratch. Instead, he cloned it from public GitHub repositories, showcasing a trend where attackers build upon existing tools, often with the help of AI.

One of the forked kits, developed by an operator named mail-argenta, demonstrated a high level of sophistication. It included features to defeat Subresource Integrity checks and added a URL-rewriting engine, showcasing the operator's ability to enhance public frameworks.

The Quietest Campaign

The third fork, black-queen, operated quietly for over a year, logging a significant number of captures without ever touching passwords. Its author, saroula01, built the campaign around Microsoft's OAuth device code flow, a legitimate sign-in path. This method, while not bypassing MFA, tricks victims into satisfying the MFA prompt on genuine Microsoft infrastructure.

AI's Role in Attack Development

A notable aspect of these operations is the use of AI-assisted development. All three campaigns showed signs of AI involvement, with some operators leaving behind evidence of AI coding sessions and model-generated code. This raises concerns about the increasing accessibility of AI tools for malicious purposes.

Defending Against These Threats

The two attack methods require different defense strategies. Phishing-resistant MFA, FIDO2, or passkeys can shut down Evilginx-based attacks, but they won't stop device code abuse. Microsoft recommends blocking device code flow wherever possible and implementing Conditional Access policies to reevaluate stolen tokens.

The Bigger Picture

This incident is a stark reminder of the evolving nature of cyber threats. With public repositories and AI tools, the barrier to entry for launching phishing campaigns has significantly lowered. As such, organizations must stay vigilant and adapt their security measures to keep pace with these rapidly evolving tactics.

In my opinion, this story underscores the importance of continuous security awareness and the need for organizations to stay informed about the latest threats and defense strategies. It's a constant cat-and-mouse game, and staying ahead requires a proactive and adaptive approach to cybersecurity.

How Hackers Bypass Microsoft 365 MFA: Evilginx & Device Code Phishing Explained (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Prof. An Powlowski

Last Updated:

Views: 6153

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Prof. An Powlowski

Birthday: 1992-09-29

Address: Apt. 994 8891 Orval Hill, Brittnyburgh, AZ 41023-0398

Phone: +26417467956738

Job: District Marketing Strategist

Hobby: Embroidery, Bodybuilding, Motor sports, Amateur radio, Wood carving, Whittling, Air sports

Introduction: My name is Prof. An Powlowski, I am a charming, helpful, attractive, good, graceful, thoughtful, vast person who loves writing and wants to share my knowledge and understanding with you.