Device Code Phishing / PhaaS
Device Code Lab (DCL) — PhaaS Infrastructure
Device Code Lab (DCL) is a Phishing-as-a-Service platform targeting Microsoft Entra ID via OAuth device code flow abuse. Infrastructure spans HostPapa, DataWagon, DigitalOcean, and AWS hosting; front-end lure pages are delivered via Cloudflare Workers and compromised third-party domains. Post-exploitation capability includes a full Outlook Web App clone, Exchange connector injection, tenant-wide transport rule creation, inbox listening, email address harvesting, SMTP lure sending, and SVG attachment generation with explicit MDE bypass. The platform is in active operational use.