Gbhackers iconGbhackersSep 16, 2026

GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation

A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are revoked. GhostCode begins with business-email social engineering rather than a conventional credential-harvesting page.

GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation

Share this story

Send the public story page.

Useful takeaways from this story.

A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are revoked.

GhostCode begins with business-email social engineering rather than a conventional credential-harvesting page.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are revoked. GhostCode begins with business-email social engineering rather than a conventional credential-harvesting page.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app