Skip to main content
← Back to Demos
phishing intermediate · 15 min

AI-Generated Microsoft 365 Device Code Phishing Lure (Storm-2945)

Microsoft attributes hotel Wi-Fi DNS-tampering campaigns to Storm-2945 (Midnight Blizzard-linked). Since July 2026 the group abuses the Microsoft Device Code login flow: victims on compromised hotel networks are steered to a legitimate-looking sign-in page and told to enter an attacker-supplied device code, handing over an OAuth token. This demo ships an AI-generated phishing lure document that mimics that M365 verification prompt; OPSWAT AI Content Inspector flags the AI-generated phishing pattern while Deep CDR sanitizes the embedded content.

Attack Technique

Device Code phishing lure (T1566.002)

MITRE ATT&CK

T1566.002 ↗

Platforms

linuxwindows

File Types

.docx

MetaDefender Capabilities

OPSWAT AI Content Inspector

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---