What is Fileless Malware? Detection & Prevention Guide
Learn how fileless malware works, why it's so effective, and essential strategies to detect and prevent these memory-based cyberattacks.
What is Device Code Phishing?
Written by: Lizzie Danielson
Published: 9/25/2026
Device code phishing is an attack in which a threat actor tricks a victim into entering an attacker-generated authentication code on a legitimate login page. The victim unknowingly authorizes the attacker’s device.
No. In device code phishing, the attacker generally isn’t intercepting the victim’s live login session. Instead, they start a legitimate device authorization flow and convince the victim to complete it for them.
It may not need to. The primary objective is often to obtain OAuth access and refresh tokens rather than the user’s password.
Because it may be real. Attackers abuse legitimate Microsoft authentication endpoints and direct victims to them with a code the attacker generated.
Yes. Microsoft Entra Conditional Access can block device code flow or restrict it to approved users and scenarios. Organizations should evaluate operational requirements before enforcing the policy.
Not necessarily. Huntress research found that Google’s device-code implementation supports a narrower set of OAuth scopes, which can significantly limit the impact compared with Microsoft’s implementation.
Block device code flow where it isn’t required, monitor identity activity, and teach users never to enter an unexpected code.
Additional Resources
Learn how fileless malware works, why it's so effective, and essential strategies to detect and prevent these memory-based cyberattacks.
Learn AWS cloud security fundamentals, shared responsibility model, key features like encryption & IAM, plus best practices for cybersecurity professionals.
Learn what cybersecurity transformation means, why it's essential for modern organizations, and how to implement a comprehensive security strategy.