Cybercriminals have elevated phishing attacks to new levels of sophistication by combining generative AI with advanced technical exploits. Security researchers at Proofpoint have identified a particularly dangerous campaign targeting Microsoft 365 accounts that abuses the legitimate OAuth 2.0 Device Authorization Grant flow, originally designed for devices without browsers like smart TVs and IoT equipment. These attacks can compromise accounts protected by two-factor authentication by tricking victims into authorizing malicious applications through genuine Microsoft authentication pages.
The OAuth device code attack begins with a phishing message claiming the victim's device needs re-authorization to access their Microsoft 365 account. Victims are directed through a fake website before landing on the official Microsoft authentication process. Because the authentication pages are genuine, users unknowingly authorize access for an attacker-controlled application rather than their own device. Once authorized, criminals receive an access token that grants API access to the Microsoft account without requiring password re-entry. Many of these attacks embed links within QR codes to bypass spam filters and encourage victims to switch to smartphones, where smaller screens and absent security software make deception harder to detect.
Beyond OAuth exploits, traditional support scams continue to succeed at scale. High-profile victims include Julia Klöckner, president of the German Bundestag, who was targeted through Signal by attackers posing as support staff. The fraudsters obtained PINs that granted access to private chats and contacts. Similar attacks impersonate Microsoft support via telephone, email, or fake browser pop-ups, claiming security issues that require installing remote maintenance software. Other persistent threats include fake Microsoft Defender renewal warnings, OneDrive phishing through shared file notifications, and delivery service scams with dynamic tracking systems that simulate real logistics processes.
Financial institutions remain primary targets, with consumer advice centers reporting numerous campaigns against Easybank, Commerzbank, Deutsche Bank, and DKB customers. These emails demand verification of mobile numbers, PhotoTAN updates, or security certificate reactivation. A particularly insidious variant arrives by physical mail, impersonating banks and requesting Postident verification. Victims unknowingly authorize loans ranging from 15,000 to 25,000 dollars. Criminals obtain the necessary personal details through fake property listings where applicants submit pay slips and employment information.
Security professionals should implement comprehensive user education programs emphasizing independent verification of all unsolicited contact. Organizations must deploy multi-factor authentication with passkeys where available, as these provide stronger protection than traditional two-factor methods. Users should manually enter website addresses rather than clicking links, leverage password managers as domain verification tools, and treat email, SMS, and messaging platforms as inherently insecure channels. Browser warnings and password manager refusals to autofill credentials serve as critical early warning indicators of fraudulent domains.
Source: https://www.pcworld.com/article/3202861/phishing-scams-ai-emails-qr-codes-fake-warnings-how-to-protect-yourself.html


