Microsoft 365 Phishing Alert: How Attackers Bypass MFA with Evilginx & Device Code Flow (2026)

In the ever-evolving landscape of cybersecurity, a recent incident has shed light on the alarming ease with which malicious actors can launch sophisticated phishing campaigns. This story, which involves a misconfigured server and three distinct phishing operations, serves as a stark reminder of the constant cat-and-mouse game between attackers and defenders.

Unveiling the Phishing Operations

The narrative begins with a simple mistake: an attacker's server, left exposed with directory listing enabled, revealed a treasure trove of information to a French security firm, Lexfo. From this one oversight, a web of connections was unraveled, leading to the discovery of three separate phishing campaigns, each employing a custom version of the open-source Evilginx proxy.

What makes this particularly fascinating is the scale and duration of these operations. The largest campaign had been active for over a year, primarily targeting corporate mailboxes. This longevity highlights the success and persistence of these phishing attempts, which often go unnoticed for extended periods.

Bypassing Security Measures

One of the key takeaways from this incident is the variety of methods used to bypass Multi-Factor Authentication (MFA). Two distinct approaches were employed, one involving proxying the live login and the other abusing a legitimate Microsoft sign-in flow. These techniques demonstrate the creativity and adaptability of attackers, who continuously seek ways to circumvent even the most robust security measures.

From my perspective, this raises a deeper question about the effectiveness of current security protocols. While MFA is undoubtedly a crucial layer of protection, it is evident that it can be compromised, especially when combined with other vulnerabilities like misconfigured servers.

The Role of AI in Attack Development

A detail that I find especially interesting is the involvement of AI in the development of these phishing operations. Signs of AI-assisted coding were found across all three campaigns, with some operators even leaving traces of their interactions with AI models. This integration of AI in cyberattacks is a worrying trend, as it suggests that attackers are leveraging advanced technologies to enhance their capabilities.

What many people don't realize is that AI can automate certain aspects of attack development, making it faster and more efficient for malicious actors. In this case, AI seems to have played a role in customizing the Evilginx proxy and generating lures, potentially reducing the barrier to entry for would-be attackers.

Implications for Defenders

For defenders, this incident serves as a wake-up call. The ease with which these campaigns were set up, using publicly available repositories and AI assistance, indicates a significant shift in the threat landscape. The report from Lexfo suggests that such attacks are likely to become more common in the coming months.

The solution, however, is not as straightforward as one might hope. The two techniques used to bypass MFA require different defensive strategies, and a single Conditional Access policy is not a silver bullet. Defenders must stay vigilant, continuously monitor for suspicious activities, and adapt their security measures to keep up with the evolving tactics of attackers.

In conclusion, this incident highlights the need for a multi-layered approach to cybersecurity. While technological advancements like AI can be a double-edged sword, they also provide opportunities for defenders to enhance their capabilities. The key lies in staying informed, adapting quickly, and collaborating across the industry to stay one step ahead of the ever-evolving threats.

Microsoft 365 Phishing Alert: How Attackers Bypass MFA with Evilginx & Device Code Flow (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Allyn Kozey

Last Updated:

Views: 5671

Rating: 4.2 / 5 (43 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Allyn Kozey

Birthday: 1993-12-21

Address: Suite 454 40343 Larson Union, Port Melia, TX 16164

Phone: +2456904400762

Job: Investor Administrator

Hobby: Sketching, Puzzles, Pet, Mountaineering, Skydiving, Dowsing, Sports

Introduction: My name is Allyn Kozey, I am a outstanding, colorful, adventurous, encouraging, zealous, tender, helpful person who loves writing and wants to share my knowledge and understanding with you.