GhostCode phishing kit uses contact forms and device-code trick to bypass MFA and hit sales teams
Researchers at eSentire say attackers use a company’s own web contact form and a staged NDA to deliver a password-gated HTML that harvests OAuth device codes, then reuse tokens to access accounts after MFA has been completed.





