Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
ReversingLabs uncovered¹ an active phishing campaign that abuses Microsoft 365’s legitimate OAuth 2.0 Device Authorization Grant flow. The phishing kit shows victims a real device code and persuades them to enter it on Microsoft’s genuine sign-in page, which authorizes an attacker-controlled device. The attackers get access to the corporate account without ever stealing a password.
The original analysis published hundreds of network IoCs. Aided by the WhoisXML API MCP Server², we extracted the unique indicators, filtered out those owned by legitimate entities, and investigated the remaining 290 — 51 domains and 239 subdomains.
Original IoCs Analyzed
Domain and IP indicators from the reported campaign
Key Findings
Email-connected domains
Additional IP addresses
String-connected domains
Malicious artifacts
These are key highlights from our analysis. The full report contains many more findings and detailed insights.
OUR RESEARCH PROCESS
- Subdomain IoC infrastructure analysis
- Domain IoC WHOIS and DNS history analysis
- Client traffic, typosquatting, and malicious intent checks
- Email-connected domain discovery
- IP address discovery and malicious IP confirmation
- String-connected domain discovery
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] https://www.reversinglabs.com/blog/device-code-phishing-campaign
- [2] https://main.whoisxmlapi.com/ai/mcp-server