A legitimate Microsoft sign-in path built for low-input devices is being repurposed as a phishing lure, shifting the attack from password theft to trusted-session abuse.