Microsoft 365 Device Code Phishing Campaign Uncovered by Researchers
A recent Microsoft 365 device code phishing campaign was uncovered by researchers at ReversingLabs, who analyzed hundreds of URLs linked to the attack. Instead of stealing passwords through a counterfeit login page, the attackers tricked victims into completing a legitimate authentication process that authorized an attacker-controlled device.
The analysis revealed three distinct client IP addresses communicating with one of the domain IoCs and 35 email-connected domains. The researchers also discovered 87 malicious IP addresses, all confirmed to be associated with various campaigns.
Further investigation using the WhoisXML API MCP Server extracted unique URLs from subdomains and removed those owned by legitimate entities. A DNS deep dive revealed one domain IoC appearing in a typosquatting group with two look-alikes, while another was likely registered with malicious intent 324 days before being identified as an IoC.
The researchers found that the domains were fairly new, created between July 2025 and June 2026, and administered by seven registrars. Most had missing data points on WHOIS API, but the remaining 16 were registered in just two countries.