Technique
MFA Device Registration
Also known as: MFA Manipulation, Device Registration
After gaining access to a victim's account -- typically via adversary-in-the-middle phishing, session hijacking, or stolen credentials -- attackers register their own authenticator app or security key as an additional MFA method. Because most platforms (including Microsoft 365) do not require MFA re…
Common attack flows
How it fits in a scam
Defense
How to defend against this
How to spot it
- Unfamiliar authenticator apps or security keys listed in your account security settings that you did not add
- Notification emails from services about new sign-in methods being registered (if the service sends them)
- Continued unauthorized access to your accounts even after you have changed your password
- Unexpected MFA prompts appearing on a device you do not recognize (indicating attacker is using your account with their enrolled MFA)
- Account activity from unfamiliar devices or locations visible in sign-in history after you believed the account was re-secured
- Being unable to remove an MFA method you do not recognize
- or finding it re-added after removal
Tools you can use
Further reading
Proofpoint
Cybersecurity Stop of the Month: MFA Manipulation -- Proofpoint details how bad actors introduce their own MFA method into compromised Microsoft 365 cloud accounts, combining MFA manipulation with OAuth application abuse for persistence.
Mitiga
Advisory on persistent MFA circumvention in an advanced BEC campaign on Microsoft 365. Documents attackers registering a second Authenticator app on a compromised executive's account within seconds, achieving full persistence that nullified MFA value.
MITRE ATT&CK
T1098.005 Account Manipulation: Device Registration -- Describes adversaries enrolling new devices in MFA systems like Duo or Okta after compromising credentials, to bypass initial MFA requirements and gain persistent access.
Obsidian Security
Behind The Breach: MFA Everywhere, Yes. MFA For Everyone, No. -- Describes how attackers exploit weak MFA registration policies by registering their own MFA methods once they gain access to an account without MFA, establishing persistent access.
Help Net Security
How attackers use and abuse Microsoft MFA -- Reports on the Mitiga finding that Microsoft does not require MFA re-challenge for accessing and changing user authentication methods, enabling persistent access even from extremely brief compromise windows.
Microsoft Security Blog
Evolved phishing: Device registration trick adds to phishers' toolbox -- Microsoft documents a large-scale phishing campaign where attackers registered unmanaged devices to Azure AD after stealing credentials, enabling lateral phishing from within the organization.