Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 4 › IT Vendor News › KnowBe4

Warning: New Phishing Kit Targets Sales Teams

KnowBe4, Friday, September 25th, 2026

A new 'GhostCode' phishing kit uses fake sales inquiries and device-code phishing to steal OAuth tokens and bypass MFA, per eSentire.

KnowBe4 reports on a new phishing kit called GhostCode, identified by eSentire researchers, that targets sales teams through a company's own web contact form to evade filters.

Attackers submit a fake business inquiry, then send a follow-up email with a password-gated HTML attachment that redirects victims to a device-code phishing page mimicking Microsoft's sign-in flow.

After the victim authenticates with MFA, attackers capture the resulting tokens, register new devices, and harvest emails. Researchers warn the technique shows MFA alone doesn't stop device-code phishing, since the stolen token carries the MFA claim forward.

more →  ·  More from KnowBe4 →