Kaspersky Report: Beware of Phishing Traps Masquerading as Law Firms

Kaspersky Report: Beware of Phishing Traps Masquerading as Law Firms - Digital Media Engineering
Kaspersky Report: Beware of Phishing Traps Masquerading as Law Firms - Digital Media Engineering

Unmasking the Crisis: How Cybercriminals Hijack Microsoft’s Authentication Mechanisms

Cybercriminals have devised a highly targeted and cunning phishing campaign that leverages Microsoft’s OAuth 2.0 Device Authorization Grant, commonly known as Device Code Flow, to breach user accounts. This campaign, active from early April to mid-May 2026, specifically aims to deceive users into revealing their credentials by mimicking legitimate legal communications. The attack not only demonstrates the evolving ingenuity of hackers but also underscores the critical importance of understanding how OAuth 2.0 Device Authorization can be manipulated to infiltrate corporate and personal accounts.

Kaspersky Report: Beware of Phishing Traps Masquerading as Law Firms - Digital Media Engineering

The Mechanics of the Attack: Step-by-Step Breakdown

The campaign kicks off with convincingly crafted phishing emails that appear to originate from a reputable legal firm. These emails contain encrypted PDF attachments secured with passwords, which, upon opening, redirect victims to malicious web pages that mimic official Microsoft login portals. The attackers meticulously design these pages to capture the user’s input during the login process, aiming to harvest Microsoft account credentials.

Kaspersky Report: Beware of Phishing Traps Masquerading as Law Firms - Digital Media Engineering

Once a user enters their login details, they are directed through multiple CAPTCHA challenges designed to bypass automated defenses. After passing these hurdles, the user encounters a single-use code prompt. When the user clicks to copy this code, it is automatically saved to their clipboard, and they are simultaneously redirected to the authentic Microsoft login page. Here, they are prompted to paste the code, believing they are completing a secure sign-in process.

Kaspersky Report: Beware of Phishing Traps Masquerading as Law Firms - Digital Media Engineering

The Exploitation of

Be the first to comment

Leave a Reply