Financial Spear Phishing Digest

OAuth/OIDC token abuse, AiTM, and enterprise notification phishing

OAuth/OIDC token abuse, AiTM, and enterprise notification phishing

Key Questions

What is OAuth device-code flow abuse and how does it enable MFA bypass?

OAuth device-code abuse involves attackers using legitimate device-code flows in four-step sequences to steal tokens and bypass MFA protections. Tools like Tycoon2FA and Kali365 exploit this for cookie theft and impersonation in services like Teams and Microsoft 365. Recent campaigns, including those from Kaspersky and others, use PDF lures with CAPTCHAs to redirect users to legitimate login flows.

How is Kali365 evolving as a Chinese PhaaS platform?

Kali365 now integrates Claude AI to automate BEC attacks by reading victim inboxes, scoring fraud potential, and sending contextually accurate payment requests. It has expanded to target AWS, Okta, and Russian platforms while using real-time tokenization, AI page generation, and encrypted delivery via RCS/iMessage. FBI advisories confirm its focus on the finance sector with 126 malicious hosts identified by Arctic Wolf.

What is Forg365 and what defensive measures are recommended against it?

Forg365 is a PhaaS platform targeting Microsoft 365 with device-code phishing, AI-assisted response drafting, and a browser extension called ForgCookie for persistent access. It integrates with legitimate email services like SES and SendGrid for evasion and uses subscription pricing. Defenses include disabling device-code flows, monitoring for IOCs like logfriend[.]com, and implementing conditional access policies as outlined in related analyses.

Device-code phishing, QR AiTM, vishing, and OAuth consent abuse continue to defeat MFA and enable Graph enumeration, token theft, MFA-device persistence, and long-lived account takeover. New delivery research shows empty-envelope M365 bypasses and malicious SVG voicemail lures at nearly 8,000 organizations, reinforcing the need to restrict active content and scrutinize allow-list exceptions.

Sources (2)
Updated Sep 15, 2026