1d ago · wiz
Attackers are abusing Entra ID device registration functionality to establish persistent access by registering rogue devices using stolen credentials, often obtained via device code phishing. Traditionally, these attacks used predictable indicators like 'DESKTOP-XXXXXXXX' device names and specific User-Agent strings, but attackers are now adopting AI-generated, benign-looking identifiers such as 'Work PC' to evade static detection. The article highlights a shift toward behavioral detection methods, including identifying anomalies in device naming conventions and correlating device code phishing with subsequent device registration events to detect these stealthier attacks.