← All briefs
high September 17, 2026

HarvestGate: A Microsoft Device-Code Phishing Kit With Gated Delivery and Automated Device Registration

Source report →

Vega Threat Research independently identified a Microsoft device-code phishing kit, tracked as HarvestGate, while investigating an HR-themed campaign in a customer environment. We traced the activity beyond the initial lure to a reusable phishing application, a varied delivery ecosystem, selective traffic routing, and automated device registration following successful authentication. The activity overlaps with the kit documented by eSentire as GhostCode; shared infrastructure and API paths confirm that both investigations track the same kit family. We retain HarvestGate, the name assigned during Vega’s independent investigation.

The campaign used personalized HR-themed PDFs delivered through Amazon SES. Messages impersonated recipients’ HR departments using leave and vacation pretexts, incorporated organizational branding, and used recipients’ names in attachment filenames. Other HarvestGate deployments used document-sharing, meeting, Microsoft 365, organization-branded, and document-security themes, showing that campaign content can change independently of the underlying kit. Links reached HarvestGate through four delivery families: compromised websites, marketing-mail infrastructure, purpose-built redirectors, and malvertising. Compromised sites used multi-segment nonsense paths, often with misspelled WordPress directories. Other chains used HubSpot click tracking, lure-themed redirectors, or an ad-network endpoint leading to an attacker-controlled relay.

Many HarvestGate landing hosts combine a role word, `access`, and an eight-character token beneath an unrelated apex domain, although variants move the token or omit `access`. The same hostname served the operator-controlled Turnstile page, phishing application, and `/api/harvester` backend. Cloudflare provided reverse-proxy and challenge services, but the content and application behind the hostname remained operator-controlled.

The gate embedded Cloudflare’s legitimate Turnstile widget and redirected successful visitors to the phishing application through a relative `return_url`. Recovered phishing pages impersonated cloud-document sharing, meeting invitations, Microsoft 365 verification, organization-branded portals, and Adobe Secure Access. The phishing page requested a legitimate Microsoft device code through the same-origin `/api/harvester` backend and displayed the resulting user code to the victim. The victim was then directed to Microsoft’s legitimate verification page, where authentication and MFA occurred directly with Microsoft. While the page polled its backend for completion, the attacker-controlled client received the resulting tokens after the victim redeemed the code.

In the investigated incident, successful device-code redemption was followed by token replay and scripted identity activity. Python-based HTTP tooling registered three attacker-controlled devices through the tenant authentication broker and attempted device enrollment. Account-derived names, sequential suffixes, a Python HTTP-library user agent, and tightly grouped requests distinguished the activity from normal enrollment. Token use continued after the victim’s password was reset, demonstrating why containment must include explicit revocation of active sessions and tokens.

DOMAIN 41
login-access-heof1k2t[.]androidpreneur[.]com
session-access-hrh9axw6[.]androidpreneur[.]com
signin-access-3qbuumoo[.]alltoyotatrucksuvparts[.]com
secure-access-ht0ysxlq[.]alltoyotatrucksuvparts[.]com
verify-access-umjlvvrx[.]alltoyotatrucksuvparts[.]com
cert-access-4kydqsdc[.]alltoyotatrucksuvparts[.]com
signin-access-ltcpr2s7[.]breakingpandora[.]com
saml-access-hjg5zb1m[.]schuelerhvac[.]com
signin-access-bpbippyw[.]geefjelevenkleur[.]com
identity-access-1uuiiymd[.]atomzilla[.]com
mfa-access-pyvxbnjc[.]atomzilla[.]com
mfa-access-ujmdufau[.]atomzilla[.]com
auth-access-iapr3p2l[.]atomzilla[.]com
auth-access-rifupwpm[.]atomzilla[.]com
auth-access-5dofmtuh[.]atomzilla[.]com
saml-access-haswvgv2[.]atomzilla[.]com
signin-access-e4gut0dm[.]atomzilla[.]com
login-access-4n34kpq9[.]atomzilla[.]com
oidc-access-ykvs3i3i[.]atomzilla[.]com
authenticate-access-unb5gtsf[.]xhscyp[.]com
validate-access-kgcdauwc[.]xhscyp[.]com
signin-access-whtc5iq4[.]accudiodesign[.]com
verify-access-6dlrv01r[.]adogabroad[.]com
verify-access-vpmpmsb3[.]adogabroad[.]com
signin-access-nlctvue6[.]adogabroad[.]com
saml-access-bgzdiwai[.]pelicol[.]com
identity-access-1w2m8s2x[.]arlingtonhousecleaning[.]com
mfa-access-zknmk8p4[.]allurepure[.]com
onestep-access-aosbgdan[.]tv-appspot[.]com
naturespluslatex[.]com
jennifertrently[.]org
foesec[.]ma
akive[.]com[.]br
meeting[.]teams-video[.]invite[.]567eco[.]cc
moon-sys-veem[.]magnoliamiracle[.]com
docs-sys-veem[.]anneaudio[.]com
swiftoaic[.]com
strninc[.]com
faktu[.]cl
email[.]ayra[.]cx
bilbakalimm[.]com
IP ADDRESS 2
5.230.71[.]19
5.230.248[.]158

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Outbound Web Request to a Device Code Harvester API Endpoint
  • Device Code Sign In Session From Multiple Source Addresses With an Unmanaged Device
  • Multiple Entra ID Device Registrations for a Single Account in a Short Window
  • Authentication Broker Sign In From a Scripted Client on an Unmanaged Device
  • Operator Controlled Turnstile Verification Route
  • Microsoft Device Code Authentication Success
  • Token Use Continuing After a Password Reset
  • Microsoft Device Login Page Visited Shortly After a First Seen External Host
  • Inbound Message Subject With Implausibly Placed Diacritic Marks