Device Code Lab (DCL) — PhaaS Infrastructure
Campaign Summary
Device Code Lab (DCL) is a Phishing-as-a-Service platform targeting Microsoft Entra ID via OAuth device code flow abuse. Infrastructure spans HostPapa, DataWagon, DigitalOcean, and AWS hosting; front-end lure pages are delivered via Cloudflare Workers and compromised third-party domains. Post-exploitation capability includes a full Outlook Web App clone, Exchange connector injection, tenant-wide transport rule creation, inbox listening, email address harvesting, SMTP lure sending, and SVG attachment generation with explicit MDE bypass. The platform is in active operational use.
Related Research
Indicators of Compromise
14 IPs · 29 domains - defanged for safe display and export