Microsoft device-code phishing and fake Claude Code ads show how attackers now abuse trusted sign-in and install flows
VPN Central [Unofficial]
April 9, 2026
Attackers are using two fast-growing tactics to compromise business and developer accounts. One campaign abuses Microsoft’s legitimate device code sign-in flow to steal OAuth tokens without stealing passwords, while another uses fake Claude Code install pages and malicious search ads to infect macOS users with AMOS stealer. Microsoft and multiple security researchers have published warnings […]
The post Microsoft device-code phishing and fake Claude Code ads show how attackers now abuse trusted sign-in and install flows appeared first on VPN Central.
Discussion in the ATmosphere