A Microsoft 365 account can be handed over through a trusted login flow, so the usual fake-page checks miss the real break. The attacker does not need to steal a password; they steer the user into approving a legitimate device-code prompt, which hands over the session and can keep access alive.
ZeroBEC says the campaign ran from late June into early July 2026 and used collaboration-style lures, a backend broker, and Microsoft Authentication Broker device-code tokens. Talos links the tooling to ARToken/EvilTokens and a reusable DEBULL layer that supports BEC, SharePoint theft, and persistent access.
The shift is that this is now commoditized PhaaS tradecraft, so the barrier is access to the kit, not deep operator skill. For Microsoft 365 and Entra ID teams, a single approved device-code request can turn into durable mailbox and SharePoint compromise, plus BEC-ready persistence.