logo

Device Code Phishing Campaign — Infrastructure Update

ID: a1d9b4f3-4361-5b57-81ce-1fba8114b72d

STIX ID: report--a1d9b4f3-4361-5b57-81ce-1fba8114b72d

Feed Name: On the Hunt

Threat Score
72/100

Date Published: 2026-03-18

Date Updated: 2026-04-19

Author: Paul Newton

...
...

This report analyzes a large-scale device-code phishing campaign hosted on Cloudflare Workers, enumerating 1,337 probed URLs (966 active), 326 unique workers.dev hostnames and 1,061 active per-victim session paths. It highlights the use of encrypted base64/AES JavaScript payloads that hide phishing content from scanners, multiple branded lure skins (Microsoft, DocuSign, Adobe), homoglyph typosquat attacker domains, and evidence that the kit is distributed to multiple operators (PhaaS).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.