security
Apr 10, 2026
By Teun
AI-Powered Phishing Campaign Bypasses OAuth with Dynamic Device Codes
Microsoft documented a phishing campaign using AI-generated lures and dynamic device code generation to bypass OAuth's 15-minute expiration window. Attackers blended traffic through Vercel and Cloudflare Workers.
Microsoft says it has documented a phishing campaign that combines AI-generated lures with a device code trick designed to work around OAuth's normal expiration window. The company said the attackers used personalized emails that looked like invoices, password notices, or requests tied to the victim's role, then sent targets to a page that generated a fresh device code only when opened.
That matters because OAuth device codes are meant to expire after a set period, which helps limit the value of a stolen code. According to Microsoft, this campaign shifts that timer to the moment the victim clicks, instead of when the email was first sent, which gives the attacker a better chance of capturing a valid login attempt before the code goes stale.
⚡ New to this?
This is a phishing campaign that uses artificial intelligence to make scam emails look more convincing and then abuses OAuth, which is a way for one app to access another service without using the user's password directly. The attackers also used a device code flow, a login method where a user enters a code on a separate page, and changed it so the code is generated only after the victim clicks. Non-experts should care because this kind of attack can lead to account access even when users never type their password into a fake site.
🦞 OpenClaw angle
If your agents use OAuth, reduce the damage of a stolen token by splitting permissions into separate scopes for mail, files, and admin actions. Require explicit human approval for any device code flow, and log when codes are generated so you can spot a code created long after an email or workflow started. Also review any allowlists for cloud hosting providers, because attackers are increasingly hiding phishing infrastructure behind services that look like normal app traffic.
Microsoft said the lure text was not generic spam. The messages were generated with AI and tailored to the target's job context, which can make them look more believable than bulk phishing email. That kind of personalization is especially useful when the attacker is trying to get a user to complete a login flow that feels routine rather than suspicious.
The infrastructure also appears to have been built to blend in with normal cloud traffic. Microsoft said the attackers routed activity through Vercel, Cloudflare Workers, and AWS Lambda, services that many organizations already allow through security filters because they are commonly used for legitimate web apps and serverless workloads. The company also linked the campaign to a phishing-as-a-service toolkit called EvilTokens.
Microsoft's report is a reminder that identity attacks are no longer just about fake login pages. Here, the goal was to capture a valid OAuth interaction, which can be more useful than a password alone because tokens can grant access to email, files, and other connected services without repeatedly asking for a password.
For defenders, the practical issue is not only whether a page looks fake, but whether the login flow itself is being abused in real time. Microsoft said the campaign used thousands of short-lived polling nodes on Railway.com to support the backend automation, showing how quickly this kind of operation can scale when cloud services are used as cover. The company published the details on April 6, 2026, and organizations can use that reporting to review where device code login is allowed and how OAuth activity is monitored.