Railway device-code phishing
campaign · campaign:railway-device-code-phishing-m365-2026
March 2026 device-code phishing campaign against 344 organisations that harvested Microsoft 365 OAuth tokens via the device-authorization flow, run from clean Railway.com PaaS IPs and attributed by Huntress to the EvilTokens phishing-as-a-service operation (Huntress, 2026-07-09).
Coverage
1
first 2026-07-10 → last 2026-08-01
Latest activity
2026-08-01
Huntress: device-code phishing and ROPC token-spray defeat M365 tenants by routing around the auth paths…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance, healthcare
Sources cited
4
2 hosts
Action items (4)
Do-now tasks recorded on the entries about Railway device-code phishing, newest first. Check the date before acting on an older one.
- Block the OAuth device-authorization (device-code) flow tenant-wide via Conditional Access, or restrict it to the named accounts that genuinely need it, this neutralises device-code phishing regardless of lure quality, because the token is never minted.2026-07-10Huntress: device-code phishing and ROPC token-spray…
- Re-scope every MFA-requiring CA policy to 'All cloud apps' and 'All client app types' (including legacy/other clients), not a per-app or per-group allow-list; an omitted app such as Azure CLI is exactly what ROPC spray rides through.2026-07-10Huntress: device-code phishing and ROPC token-spray…
- Enable client-level strong-auth enforcement (userStrongAuthClientAuthNRequired) to block ROPC flows from succeeding even with valid credentials, and audit for CA policies set to report-only that were never enforced.2026-07-10Huntress: device-code phishing and ROPC token-spray…
- Hunt sign-in logs for successful ROPC/legacy-auth authentications to Azure resource apps with no corresponding interactive MFA challenge, and for device-code completion events not tied to a genuine input-constrained device.2026-07-10Huntress: device-code phishing and ROPC token-spray…
Defender insights
What each entry about Railway device-code phishing tells a defender to do, newest first.
Latest update · triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (6 across 7 tactics)
6 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts: Cloud Accounts · Phishing: Spearphishing Link
- PersistenceValid Accounts: Cloud Accounts · Modify Authentication Process: Multi-Factor Authentication
- Privilege EscalationValid Accounts: Cloud Accounts
- StealthValid Accounts: Cloud Accounts
- Defense ImpairmentModify Authentication Process: Multi-Factor Authentication
- Credential AccessBrute Force: Password Spraying · Steal Application Access Token · Modify Authentication Process: Multi-Factor Authentication
- Lateral MovementUse Alternate Authentication Material: Application Access Token
Initial Access TA0001
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
T1566.002Phishing: Spearphishing Link×1
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
Persistence TA0003
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
Privilege Escalation TA0004
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
Stealth TA0005
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
Defense Impairment TA0112
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
Credential Access TA0006
T1110.003Brute Force: Password Spraying×1
Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
T1528Steal Application Access Token×1
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
Lateral Movement TA0008
T1550.001Use Alternate Authentication Material: Application Access Token×1
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.
Evidence: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns · ATT&CK page ↗
Entries about Railway device-code phishing (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- huntress.com3 (75%)
- thehackernews.com1 (25%)
All cited sources (4)
- huntress.comHuntresshttps://www.huntress.com/blog/conditional-access-misconfigurations
- huntress.comHuntresshttps://www.huntress.com/blog/device-code-phishing-evolving-threats
- huntress.comHuntresshttps://www.huntress.com/blog/lshiy-password-spray-attack
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html