GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation
A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are revoked. GhostCode begins with business-email social engineering rather than a conventional credential-harvesting page.
