Weekly threat recap: GhostCode credential theft, TrustSink rogue Entra MFA abuse, and Fast Flux phishing led activity. Also covered KREMLIN, RatHat, and APT/supply-chain ops. #GhostCode #TrustSink #FastFlux

Weekly threat recap: GhostCode credential theft, TrustSink rogue Entra MFA abuse, and Fast Flux phishing led activity. Also covered KREMLIN, RatHat, and APT/supply-chain ops. #GhostCode #TrustSink #FastFlux
Security researchers uncovered a new GhostCode phishing kit. Learn how the GhostCode phishing kit bypasses MFA to hijack enterprise Microsoft 365 accounts.
The new GhostCode turns Microsoft’s legitimate device authentication flow against its users, stealing valid tokens after MFA and registering attacker-controlled devices in minutes.
Listen/Read: hackread.com/ghostcode-ph...
GhostCode phishing used business outreach and contact forms to abuse Microsoft device codes, steal tokens, and get a Primary Refresh Token in under 78 seconds, using obfuscation, proxy rotation, and trusted services. #GhostCode #Storm2372