The recent phishing campaign observed by security researchers has brought into focus an attack vector that uses Microsoft's legitimate device code flow to compromise Microsoft 365 accounts. Unlike traditional attacks that rely on fake login pages, this threat uses collaboration-themed lures to trick users into entering a code on the official Microsoft login screen. The tool known as DEBULL has become the center of this new wave, operating between late June and early July 2026, and leveraging the trust that professionals place in standard authentication flows.
The attack mechanism is particularly insidious because it does not require the user to hand over their credentials directly. Instead, attackers send a fake collaboration message that, when opened, prompts the user to authenticate their session in an application using the device code. Since this is a legitimate Microsoft screen, corporate defenses based on detecting fake pages fail to identify the threat. Once the user enters the code, the attacker obtains an access token that allows them to control the M365 account, including email, files, and settings, without needing the password.
This type of attack underscores the need to strengthen cybersecurity in organizations, especially when using cloud environments like Azure or Microsoft collaboration services. The sophistication of DEBULL demonstrates that cybercriminals are evolving toward techniques that abuse legitimate processes, making traditional protection solutions insufficient. Companies must adopt a multi-layered approach that includes monitoring atypical logins, conditional access policies, and continuous employee training against this type of social engineering.
In this context, having a technology partner that understands the complexities of M365 security is essential. Companies like Q2BSTUDIO offer cybersecurity and pentesting services that help identify vulnerabilities in authentication processes and cloud environment configurations. Additionally, their expertise in AWS and Azure cloud services helps design secure architectures that minimize the risk of abuse of flows like the device code flow. Implementing artificial intelligence for businesses can also play a key role in early detection of anomalous patterns in user sessions, enabling automated responses to impersonation attempts.
Beyond reacting to specific threats, a comprehensive protection strategy must combine periodic audits, custom software development to integrate personalized security controls, and business intelligence solutions that help visualize risks in real time. For example, using Power BI, it is possible to create dashboards that monitor logins from unmanaged devices or from unusual geographic locations. Likewise, custom application development allows for implementing advanced multi-factor authentication policies that reduce the attack surface. AI agents, trained to recognize suspicious behavior, can act as an additional defense layer in environments where users interact with collaborative services.
In conclusion, the campaign abusing Microsoft's device code flow is a reminder that security cannot be taken for granted. Organizations must invest in specialized tools and advice to stay ahead of these emerging threats. With a proactive approach and support from companies like Q2BSTUDIO —which integrate cloud services, cybersecurity, artificial intelligence, and software development— it is possible to build a more resilient digital ecosystem against attacks that, like DEBULL, exploit trust in legitimate processes.

.jpg)



