CodeStorm phishing kit uses real-time replay to bypass M365 authentication
Security firm ZeroBEC has identified a sophisticated phishing campaign dubbed CodeStorm that targets Microsoft 365 organizations using tenant-aware credential replay and bypass techniques. The campaign uses infrastructure including Tencent Cloud and Cloudflare Turnstile to evade detection while mimicking legitimate voicemail notifications.
Key Takeaways
- Campaign leverages 'conversation stuffing' with hidden email threads to trick automated gateways into misclassifying phishing as low-risk thread hijacks.
- Phishing kit executes real-time credential replay, submitting stolen data to Microsoft immediately to validate authenticity and mirror official error messages.
- Multi-stage infrastructure includes Cloudflare Turnstile for scanner evasion and second-stage JavaScript payloads hosted on Tencent Cloud Object Storage.
- Administrative logs for affected tenants show active 'OfficeHome' authentication failures under error code 50126 during the credential validation process.
Why It Matters
This campaign signals an evolution toward 'adversary-in-the-middle' techniques that turn standard security protocols against the user. By integrating home-realm discovery and real-time validation, attackers bypass the static protections of legacy email filters and basic MFA. For the streaming and broader media ecosystem, this increases the risk of corporate account takeovers that can lead to high-value intellectual property theft via SharePoint and OneDrive. Executives should watch for a shift from password-based attacks to session-token theft, which requires a transition toward FIDO2-compliant hardware keys or phishing-resistant authentication methods to mitigate emerging credential replay trends.
Additional Context
The rise of CodeStorm aligns with a broader industrialization of Phishing-as-a-Service (PhaaS) platforms observed in 2026. Per Fortgale (April 2026), kits such as EvilTokens and Rockstar 2FA have commoditized MFA bypass, allowing low-skill operators to rent infrastructure via Telegram for approximately €200 per two-week window. These platforms frequently utilize generative AI to automate post-compromise activity, such as identifying financial threads in a victim’s mailbox and generating persuasive Business Email Compromise (BEC) lures in under five minutes. Related intelligence from Microsoft and BleepingComputer in July 2026 highlights a surge in 'device code phishing' variants like Jalisco and OmegaLord. These kits abuse Microsoft’s device-pairing features intended for smart TVs and conference room displays to generate OAuth access tokens. Unlike traditional credential theft, this method does not require a password; once the victim enters a six-character code on a legitimate Microsoft page, the attacker gains persistent access to Outlook, Teams, and SharePoint. Federal warnings, including an FBI advisory from May 2021 (PSA260521), suggest that these techniques are now standard for both nation-state actors and financially motivated groups. Security firm ReliaQuest noted that exfiltration of data following such token theft often occurs in as little as six minutes. Consequently, security teams are increasingly advised to restrict OAuth device authorization and lower default Entra ID device registration limits to reduce the attack surface for these automated replay and hijacking frameworks.
Read full article at x.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source