Kaspersky warns for a new, sophisticated phishing campaign (Phishing), which exploits official Microsoft infrastructure. This method renders useless the classic security advice that urges users to simply check the website name (domain name).
How the scam works
The trap: Attackers send an email that appears to be a notification from a law firm, attaching a locked PDF file.
The link: Inside the PDF is a link to a supposed service called “LawConnect.”
The redirection: Although the link appears to lead to an official Microsoft page, it uses malicious parameters that redirect the user to a fake website.
The interception: The fake page asks the victim to copy a unique code and paste it into the real Microsoft (Microsoft Identity Platform) login form. In doing so, the user unwittingly gives access to their account to the malicious application.
The vulnerability of the Protocol
The attack exploits the Device Authorization Grant protocol designed to facilitate login to keyboard-less devices (e.g. Smart TVs, printers) by entering a temporary password.
Protection measures for users
Reject requests: Never approve connection requests that you did not initiate yourself.
Pay attention to the codes: Do not enter codes received from suspicious messages, even if the link looks official.
Checking URLs: Before clicking, check if the URL contains suspicious redirects (such as redirect_uri or return_url).
Instructions for businesses
Kaspersky recommends that companies globally disable the Device Code Flow feature via Conditional Access policies in Microsoft Entra ID, if it is not absolutely necessary.
At the same time, it is recommended to monitor DeviceCodeSignIn events and enforce strict device compliance checks.
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.

