Disclaimer: All research and opinions expressed here are my own and are independent of any employer or organisation.

Tracked Campaigns

2 campaigns tracked - IOCs, summaries, and links to related research

campaign-dcl-05-2026 active

Device Code Phishing / PhaaS

Device Code Lab (DCL) — PhaaS Infrastructure

Device Code Lab (DCL) is a Phishing-as-a-Service platform targeting Microsoft Entra ID via OAuth device code flow abuse. Infrastructure spans HostPapa, DataWagon, DigitalOcean, and AWS hosting; front-end lure pages are delivered via Cloudflare Workers and compromised third-party domains. Post-exploitation capability includes a full Outlook Web App clone, Exchange connector injection, tenant-wide transport rule creation, inbox listening, email address harvesting, SMTP lure sending, and SVG attachment generation with explicit MDE bypass. The platform is in active operational use.

29 domains Device Code Lab — Deep Dive Device Code Lab — Infrastructu…
First seen Updated
campaign-device-code-03-2026 active

Device Code Phishing

Device Code Phishing via Cloudflare Workers — PhaaS Campaign

A large-scale Phishing-as-a-Service (PhaaS) campaign abusing Microsoft Device Code Authentication, delivered via Cloudflare Workers. Victims receive phishing emails with links to workers.dev domains that serve branded lure pages (Adobe, DocuSign, Outlook) containing real Microsoft device codes. When the victim enters the code at the Microsoft device login portal, the attacker's backend silently exchanges it for an access token and refresh token. Infrastructure spans 326 unique workers.dev hostnames across 1,337 known URLs, with per-victim session tokens baked into every phishing link.

525 domains Uncovering a New Device Code P… Device Code Phishing Campaign …
First seen Updated