Knowbe4 iconKnowbe4Sep 25, 2026 ~3 min source read

GhostCode phishing kit uses contact forms and device-code trick to bypass MFA and hit sales teams

Researchers at eSentire say attackers use a company’s own web contact form and a staged NDA to deliver a password-gated HTML that harvests OAuth device codes, then reuse tokens to access accounts after MFA has been completed.

Warning: New Phishing Kit Targets Sales Teams

Share this story

Send the public story page.

Useful takeaways from this story.

Attackers begin by submitting a legitimate-looking inquiry through a company contact form (Salesforce) so initial messages evade email filters.

A follow-up email delivers a WeTransfer link to a password-protected HTML file that launches in the victim browser and redirects to a device-code phishing page.

# What happened Researchers at eSentire uncovered a phishing kit called "GhostCode" that specifically targets sales teams. The attack chain starts with a normal-looking business inquiry submitted through the target company's web contact form, which helps the initial outreach bypass email security filters.

# How the attack unfolds

  1. Threat actor uses the target's contact form (example: Salesforce) to initiate a conversation.
  2. After the sales team replies, the attacker promises a follow-up email with an NDA.
  3. The follow-up email contains a WeTransfer link to a password-gated HTML attachment.
  4. When the victim opens the HTML file, it launches in the browser and redirects to a device-code phishing page.
  5. The phishing page tells the victim to copy a code and enter it into Microsoft's legitimate sign-in page to "authenticate."
  1. Attackers register devices, acquire long-living tokens, and harvest emails for further abuse.

# Why MFA didn't stop this The attack uses the OAuth device-code flow in a social-engineered context. eSentire explains that once a victim completes MFA on the legitimate sign-in page, the resulting token contains the MFA claim. Attackers with the token can make API calls that pass MFA checks without the user re-authenticating. In other words, stealing a device code and exchanging it for a token lets the attacker piggyback on the completed MFA.

# What GhostCode targets and why sales teams are vulnerable

# Concrete technical elements observed

  • Initial vector: company web contact form (example cited: Salesforce).
  • Delivery vehicle: WeTransfer link to a password-protected HTML attachment.
  • Exploit technique: HTML launches in browser and redirects to a device-code phishing page that mimics legitimate authentication steps.
  • Outcome: attackers obtain authentication tokens, register devices, and harvest emails and long-living tokens.

# Practical defensive steps implied by the report

  • Verify document delivery channels outside the initial thread (call the requester or confirm via known business contact details) before opening attachments or copying codes.
  • Review processes around handling contact-form leads. Consider additional controls or human verification before auto-forwarding or treating them as trusted prospects.
  • Monitor for new device registrations, anomalous token use, and long-lived tokens in identity logs. Prioritize investigations where tokens show broad API activity without re-authentication.

# Closing summary GhostCode combines standard social engineering (phony NDAs and file transfers) with a device-code phishing technique that captures OAuth tokens after MFA completes. Because the campaign begins through legitimate contact forms and hands victims a seemingly normal sign-in flow, organizations that rely on MFA as the primary defense should treat device-code phishing as a distinct risk vector and adjust lead-handling and identity monitoring accordingly.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app