Threat Reports

Read other reports

A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign

ReversingLabs uncovered¹ an active phishing campaign that abuses Microsoft 365’s legitimate OAuth 2.0 Device Authorization Grant flow. The phishing kit shows victims a real device code and persuades them to enter it on Microsoft’s genuine sign-in page, which authorizes an attacker-controlled device. The attackers get access to the corporate account without ever stealing a password.

The original analysis published hundreds of network IoCs. Aided by the WhoisXML API MCP Server², we extracted the unique indicators, filtered out those owned by legitimate entities, and investigated the remaining 290 — 51 domains and 239 subdomains.

290

Original IoCs Analyzed

Domain and IP indicators from the reported campaign

Key Findings

35

Email-connected domains

87

Additional IP addresses

757

String-connected domains

88

Malicious artifacts

These are key highlights from our analysis. The full report contains many more findings and detailed insights.

OUR RESEARCH PROCESS

  • Subdomain IoC infrastructure analysis
  • Domain IoC WHOIS and DNS history analysis
  • Client traffic, typosquatting, and malicious intent checks
  • Email-connected domain discovery
  • IP address discovery and malicious IP confirmation
  • String-connected domain discovery

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.reversinglabs.com/blog/device-code-phishing-campaign
  • [2] https://main.whoisxmlapi.com/ai/mcp-server

Latest Reports

Read other reports

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.