MaximAlert

Thought Leadership

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Dark Reading

August 4, 2026

Visit Count : 11

Phishing is evolving faster than it has in a long, long time.

Email-based phishing undisputedly has been the most dominant means of social engineering in the 21st century. It hasn't changed much in that time, and attackers followed pretty much the same basic principles, evolving mostly in their efficacy and ease of operation.

In the first half of 2026, though, attackers have been graduating in droves to relatively newer, less obvious phishing techniques. Crowdstrike tracked a doubling of voice phishing (vishing) attacks in this period, according to its newly released 2026 Threat Hunting Report. In the same time period, it tracked a 15-fold increase in device code phishing. Both techniques are helping state-sponsored threat actors and cybercriminal groups bypass traditional security controls.

Device Code Phishing Explodes

On Oct. 13, 2020, the high-profile Microsoft researcher Nestori Syynimaa published a blog post in which he invented the technique now known as device code phishing.

It took a long time for anyone else to catch on. Only in August 2024 did a Russian nation-state threat actor, tracked by Microsoft as "Storm-2372," have the bright idea to try out Syynimaa's technique in a proper cyberattack campaign. By doing so, it managed to compromise organizations across major industries — government, defense, energy, and others — and broad regions — North America, Europe, Africa, and the Middle East — before Microsoft finally discovered and described it in a public blog post the following year.

Slowly over the course of 2025, the technique trickled down from the Russian state to cybercriminal groups. Multiple research groups independently noticed a steady rise in device code phishing as 2025 went on, most notably by actors associated with Tycoon 2FA, the world's leading phishing operation at the time.

In 2026, device code phishing is becoming mainstream. CrowdStrike observed 15 times more such attacks through the first half of this year than it had through the second half of last. In particular, it noted that attackers are using the technique to compromise cloud identities.

"A diverse set" of cybercriminals is doing it now, CrowdStrike wrote, the most prominent among them being the Russian advanced persistent threat (APT) group known as Cozy Bear. CrowdStrike describes other financially motivated device code phishers as followers of Cozy Bear's model, "deploying dedicated device code and session management infrastructure, leveraging legitimate cloud-based hosting services, and delivering device code phishing pages via Entra ID application OAuth redirection at scale."

Hackers Choose Vishing for Stealthier Attacks

Vishing was already on the rise going into 2025, and lately its momentum has been accelerating. CrowdStrike measured a 134% increase in vishing from 2024 to 2025. From H2 2025 to H1 2026, vishing rates doubled.

Two of the biggest threat actors utilizing vishing today are tracked by CrowdStrike as "Cordial Spider" and "Snarky Spider." Each uses the technique to ultimately gain access to victims' single sign-on (SSO)-integrated software-as-a-service (SaaS) applications — valuable sources of corporate secrets.

They do it by first directing victims to SSO-themed adversary-in-the-middle (AiTM) pages on their mobile devices. The attackers tailor the phishing pages to the victims they're interested in, and attacking them on their mobile devices often means avoiding the security software victims often install only on their laptop and desktop computers.

Once victims hand over their credentials and multifactor authentication (MFA) codes, the threat actors authenticate and then attempt to register their own MFA devices for persistent access to victims' networks. New device registration is a meaningful early-stage signal defenders look for in these attacks, as CrowdStrike observed in a case back in February. In four minutes flat, Cordial Spider had successfully vished a victim, authenticated to their network, and registered a new allowed MFA device. The new device listing raised alarms, though, alerting the victim and empowering them to boot out their attacker only 12 minutes later.

Without that kind of diligent detection, vishing can be highly effective. It bypasses traditional email security protections and leaves fewer footprints behind for cyber defenders to analyze. As an added benefit, victims are less likely to be aware of vishing or practiced at avoiding it.

"What they've realized is that there's technical controls in place for email phishing," Adam Meyers, head of counter adversary operations at CrowdStrike, said of vishers in a July 30 press webinar. "We're scanning emails. We've got a whole host of different technologies out there: Proofpoint, Mimecast, Sublime, Abnormal. All of these different products have been built to kind of handle email based phishing attacks."

"Targeting humans, targeting the help desk, is way more effective" than technical hacking, he says. With new kinds of phishing mindgames, "You don't have to hack in, you just have to log in."

contact