AUTHOR

Trevor Hilligoss

Chief Intelligence Officer
Trevor served nine years in the U.S. Army and has an extensive background in federal law enforcement, tracking threat actors for both the DoD and FBI. He serves in an advisory capacity for multiple cybersecurity-focused non-profits. He has spoken at numerous US and international cyber conferences, holds multiple federal and industry certifications in the field of cybersecurity, and is a recipient of the President’s Volunteer Service Award for volunteer service aimed at countering cyber threats. Trevor is SpyCloud’s Chief Intelligence Officer and leads SpyCloud Labs.
Illustration of device code phishing attack bypassing multi-factor authentication.

Device Code Phishing: The AiTM Attack That Bypasses MFA

Device code phishing is a fast-growing adversary-in-the-middle (AiTM) attack that exploits OAuth 2.0 device flow to harvest access and refresh tokens — bypassing MFA. SpyCloud Labs researchers break down how it works, what attackers do with stolen tokens, and how to detect and shut down compromised sessions.

Read More »

Act on what criminals know about your business

Going passwordless changes your attack surface. Explore session hijacking prevention

X